Hesperbot-Trojan-Warning.pdf
ID: 05356ac4-c638-4086-a4d5-6282d82985b3
STIX ID: report--05356ac4-c638-4086-a4d5-6282d82985b3
Threat Score
78/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
**Executive summary:** This white paper presents a technical analysis of the Win32/Spy.Hesperbot banking Trojan used in active phishing campaigns across Turkey, the Czech Republic, Portugal and the United Kingdom; Hesperbot employs a modular architecture (dropper, core, interception and injection modules), a local proxy MITM with fake certificate handling, keylogging, screenshot/video capture, hidden VNC for remote access and a mobile component to steal mTANs, and the report includes targeted bank lists, campaign timeline and IoCs (domains and MD5s).
