Shylock
Aliases: Caphaw
- Malware type
- trojan, botnet
- Family
- Malware family
- Last IoC activity
- 2026-05-21 02:55:18
- Profile updated
- 2026-07-07 12:35:58
Targeted industries: financial-services
Targeted regions: country_code:us country_code:gb
Context
Shylock, also known as Caphaw, is a banking trojan known for targeting financial institutions primarily in the US and UK. It is capable of stealing credentials and operates as part of a botnet.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Shylock_Auto (yara-rule)
Reports & references
- web.archive.org — Security Vendors Take Action Against Hidden Lynx Malware (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Shylock (report)
- securityintelligence.com — Merchant Of Fraud Returns Shylock Polymorphic Financial Malware Infections On The Rise (report)
- virusbulletin.com — Paper Pluginer Caphaw (report)
- malwarereversing.wordpress.com — Debugging Injected Code With Ida Pro (report)
- europol.europa.eu — Global Action Targeting Shylock Malware (report)
- zscaler.com — New Wave Win32Caphaw Attacks Threatlabz Analysis (report)
- contagiodump.blogspot.com — Sept 21 Greedy Shylock Financial (report)
- ESET — Caphaw Attacking Major European Banks With Webinject Plugin (report)
- securityintelligence.com — Shylocks New Trick Evading Malware Researchers (report)