Shylock

Aliases: Caphaw

Malware type
trojan, botnet
Family
Malware family
Last IoC activity
2026-05-21 02:55:18
Profile updated
2026-07-07 12:35:58

Targeted industries: financial-services

Targeted regions: country_code:us country_code:gb

Context

Shylock, also known as Caphaw, is a banking trojan known for targeting financial institutions primarily in the US and UK. It is capable of stealing credentials and operates as part of a botnet.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Shylock_Auto (yara-rule)

Reports & references

  • web.archive.org — Security Vendors Take Action Against Hidden Lynx Malware (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Shylock (report)
  • securityintelligence.com — Merchant Of Fraud Returns Shylock Polymorphic Financial Malware Infections On The Rise (report)
  • virusbulletin.com — Paper Pluginer Caphaw (report)
  • malwarereversing.wordpress.com — Debugging Injected Code With Ida Pro (report)
  • europol.europa.eu — Global Action Targeting Shylock Malware (report)
  • zscaler.com — New Wave Win32Caphaw Attacks Threatlabz Analysis (report)
  • contagiodump.blogspot.com — Sept 21 Greedy Shylock Financial (report)
  • ESET — Caphaw Attacking Major European Banks With Webinject Plugin (report)
  • securityintelligence.com — Shylocks New Trick Evading Malware Researchers (report)

External references