Overview
Families like Zeus descendants inject HTML into the real banking page, so the victim sees their own bank and types normally.\nForm-grabbing captures the session cookie at the same time, and money mules move the funds before the user notices.\nModern variants add a virtual-environment check to avoid analysts.
Indicators of Compromise
Signals that suggest this is present on a system.
- Injected form fields on known banking domains
- Unexpected certificates installed in the user store
- Automated transfers initiated outside business hours