Vawtrak
Aliases: Catch, NeverQuest, grabnew
- First seen
- 2013-10-10 00:00:00
- Malware type
- botnet, credential-stealer, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:37:15
- Profile updated
- 2026-07-07 12:54:53
Targeted industries: financial-services
Context
Vawtrak, also known as Catch, NeverQuest, and grabnew, is a banking trojan used in cybercrime operations. It is designed to steal credentials and other sensitive information from victims, primarily targeting the financial services industry. Vawtrak is often distributed through phishing campaigns and exploit kits, forming part of a broader botnet infrastructure.
Detection coverage
- 6 YARA rules
Detection rules
- HARFANGLAB_Xdspy_Xdigo (yara-rule)
- SEKOIA_Bot_Lin_Kinsing_Strings (yara-rule)
- SEKOIA_Platypus_Winlinmac_Strings (yara-rule)
- SEKOIA_Bot_Lin_Xorddos_Strings (yara-rule)
- SEKOIA_Bot_Lin_Lucifer_Strings (yara-rule)
- MALPEDIA_Win_Vawtrak_Auto (yara-rule)
Reports & references
- CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
- secureworks.com — Dyre Banking Trojan (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- securityintelligence.com — From Ramnit To Bumblebee Via Neverquest (report)
- fidelissecurity.com — Me And Mr Robot Tracking Actor Behind Man1 Crypter (report)
- blog.fox-it.com — Bokbot The Rebirth Of A Banker (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Vawtrak (report)
- thehackernews.com — Neverquest Fbi Hacker (report)
- info.phishlabs.com — The Unrelenting Evolution Of Vawtrak (report)
- threatpost.com — 117595 (report)
- blueliv.com — Network Insights Into Vawtrak V2 (report)
- medium.com — Vawtrak Malware 824818C1837 (report)