Thorough analysis of this new kid on the malware block.
Times are changing rapidly for banking trojans. Some prominent arrests and at least partially successful takedowns have left space for new criminal entrepreneurs in this malicious, yet highly profitable market. 'Shifu' seems to have
filled part of this space.
First by Fortinet researchers Floser Bacurio Jr and Wayne Low, who analysed a recent sample of Shifu.
From the dropper, via various techniques used to frustrate automated and manual analysis, to the ways in which the malware steals banking credentials and other private data and can even destroy itself and the operating system it runs
on: Floser and Wayne take the reader step by step through the malware, making this an essential read for anyone having to deal with Shifu infections.