logo

Hesperbot-Trojan-Warning.pdf

ID: 05356ac4-c638-4086-a4d5-6282d82985b3

STIX ID: report--05356ac4-c638-4086-a4d5-6282d82985b3

Threat Score

78/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
**Executive summary:** This white paper presents a technical analysis of the Win32/Spy.Hesperbot banking Trojan used in active phishing campaigns across Turkey, the Czech Republic, Portugal and the United Kingdom; Hesperbot employs a modular architecture (dropper, core, interception and injection modules), a local proxy MITM with fake certificate handling, keylogging, screenshot/video capture, hidden VNC for remote access and a mobile component to steal mTANs, and the report includes targeted bank lists, campaign timeline and IoCs (domains and MD5s).