Vawtrak

Aliases: Catch, NeverQuest, grabnew

First seen
2013-10-10 00:00:00
Malware type
botnet, credential-stealer, trojan
Family
Malware family
Last IoC activity
2026-07-22 00:37:15
Profile updated
2026-07-07 12:54:53

Targeted industries: financial-services

Context

Vawtrak, also known as Catch, NeverQuest, and grabnew, is a banking trojan used in cybercrime operations. It is designed to steal credentials and other sensitive information from victims, primarily targeting the financial services industry. Vawtrak is often distributed through phishing campaigns and exploit kits, forming part of a broader botnet infrastructure.

Detection coverage

  • 6 YARA rules

Detection rules

  • HARFANGLAB_Xdspy_Xdigo (yara-rule)
  • SEKOIA_Bot_Lin_Kinsing_Strings (yara-rule)
  • SEKOIA_Platypus_Winlinmac_Strings (yara-rule)
  • SEKOIA_Bot_Lin_Xorddos_Strings (yara-rule)
  • SEKOIA_Bot_Lin_Lucifer_Strings (yara-rule)
  • MALPEDIA_Win_Vawtrak_Auto (yara-rule)

Reports & references

  • CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
  • secureworks.com — Dyre Banking Trojan (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • securityintelligence.com — From Ramnit To Bumblebee Via Neverquest (report)
  • fidelissecurity.com — Me And Mr Robot Tracking Actor Behind Man1 Crypter (report)
  • blog.fox-it.com — Bokbot The Rebirth Of A Banker (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Vawtrak (report)
  • thehackernews.com — Neverquest Fbi Hacker (report)
  • info.phishlabs.com — The Unrelenting Evolution Of Vawtrak (report)
  • threatpost.com — 117595 (report)
  • blueliv.com — Network Insights Into Vawtrak V2 (report)
  • medium.com — Vawtrak Malware 824818C1837 (report)

External references