{"id":1319,"date":"2016-11-02T04:31:41","date_gmt":"2016-11-02T04:31:41","guid":{"rendered":"https:\/\/antivirus.comodo.com\/blog\/?p=1319"},"modified":"2025-04-08T19:05:04","modified_gmt":"2025-04-08T13:35:04","slug":"cloudfanta-malware-steals-banking-credentials","status":"publish","type":"post","link":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/","title":{"rendered":"CloudFanta Malware Bypasses Virtual Keyboard Security, Steals Banking Credentials"},"content":{"rendered":"<p>A new malware is suspected to have stolen more than 26,000 worth of email credentials. Dubbed CloudFanta, the malware has been targeting users mostly in Brazil till now. It has also been sending emails from the victims email ID and also monitoring their online banking activities.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3121\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/cloudfanta-malware.jpg\" alt=\"cloudfanta malware\" width=\"650\" height=\"300\" srcset=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/cloudfanta-malware.jpg 650w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/cloudfanta-malware-300x138.jpg 300w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/cloudfanta-malware-225x104.jpg 225w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>The cyber criminals who have unleashed CloudFanta had initiated the attack typically through spearphishing emails. Victims were tempted to open an attachment or click on a link which initiated the malware infection. The unique factor in this attack is that the malware uses the SugarSync cloud storage app for delivering a downloader file. SugarSync is a cloud-based service that allows active synchronization of files across devices. The downloader is a &#8220;.jar&#8221; ( a Java Archive) file that downloads Dynamic Linked Library (DLL) files having a \u201c.png\u201d extension. The downloader too uses the SugarSync cloud storage app. These files are renamed with a \u201c.twerk\u201d extension and then used for malicious activities \u2013 stealing email credentials, sending emails and monitoring banking transactions.<\/p>\n<p>SugarSync had been used for hosting the drive-by-download files. The malware had also been undetectable by typical <a href=\"https:\/\/antivirus.comodo.com\/free-antivirus.php\" target=\"_blank\" rel=\"noopener\"><strong>Cloud Antivirus<\/strong> <strong>solutions<\/strong><\/a> as it had used <a title=\"\u201dWhat\" href=\"https:\/\/www.instantssl.com\/ssl.html\" target=\"_blank\" rel=\"noopener nofollow\">SSL<\/a>\/HTTPS for communicating with the SugarSync service. In these attacks, the perpetrators also used Dropbox for hosting the malware.<\/p>\n<p>This attack portrays effective use of cloud-based services for malware attacks. The Banking Trojan \u2013 Admin.twerk had been used in this attack, and the victims were users who visited the websites of the following banks in Brazil : Caixa, Banco Bradesco, Banco do Brasil, bb.com.br, and Sicredi.<\/p>\n<p><strong>How the CloudFanta malware works?<\/strong><\/p>\n<p>The Admin.twerk trojan gained complete administrative privileges by disabling the User Account Control of the infected machine. The malware searched the victims&#8217;s machine for email addresses and passwords.<\/p>\n<p>When a user enters the login credentials, the malware redirects the sign-in page to a phishing sign-in page, where the data gets stolen and transferred. The webpage then reverts back to the original\/genuine\/sign-in webpage.<\/p>\n<p><strong>Virtual Keyboard Security Bypassed<\/strong><\/p>\n<p>The CloudFanta also bypasses the virtual keyboard security feature used in banking websites. Every single mouse click gets stored as snapshots, and the cyber criminals would be able to find out the password from the mouse clicks. (<a href=\"https:\/\/www.ppi.edu.pk\/diazepam-online\/\">Valium<\/a>) <\/p>\n<p><a href=\"https:\/\/blog.comodo.com\/cybersecurity\/cyber-security-in-us\/\" rel=\"noopener\" target=\"_blank\" title=\"cyber security\">Cyber security<\/a> experts foresee a drastic increase in cloud malware campaigns, as more enterprises adopt cloud apps to expand their businesses.<\/p>\n<p><strong>Preventive Measures to Protect Cloud Apps<\/strong><\/p>\n<ul>\n<li>Install <a href=\"https:\/\/antivirus.comodo.com\/cloud-antivirus.php\">Cloud Antivirus<\/a> security solutions to address malware in cloud services<\/li>\n<li>Always keep the operating systems and Cloud Antivirus solutions updated<\/li>\n<li>Utilize a <a href=\"https:\/\/www.itarian.com\/patch-management.php\" target=\"_blank\">patch management<\/a> system<\/li>\n<li>Track usage of cloud services<\/li>\n<li>Ensure regular backup of content in the cloud<\/li>\n<li>Make two-factor authentication mandatory for accessing email and banking accounts<\/li>\n<li>Educate users on internet security and safe internet practices. Instruct users on not to open attachments from unknown sources or click on links in mails from doubtful sources.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/antivirus.comodo.com\/download\/thank-you.php?prod=cloud-antivirus&#038;track=16678&#038;af=16678\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2018\/04\/Comodo-Free-Antivirus.png\" alt=\"comodo antivirus\"\/><\/a><\/p>\n<p><a href=\"https:\/\/secure.nurd.com\/home\/purchase.php?pid=109&#038;af=16166\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2020\/08\/complete-antivirus.png\" alt=\"comodo antivirus\" width=\"650\" height=\"83\" \/><\/a><\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n<strong><strong>Related Resources:<\/strong><br \/>\n<\/strong><\/p>\n<p><strong><a href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/five-best-virus-and-malware-removal-tools\/\" target=\"blank\">https:\/\/antivirus.comodo.com\/blog\/computer-safety\/five-best-virus-and-malware-removal-tools\/<\/a><\/strong><\/p>\n<p><strong><a href=\"https:\/\/cwatch.comodo.com\/website-backup\/\" target=\"blank\" rel=\"noopener\" target=\"_blank\">Website Backup<\/a><\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new malware is suspected to have stolen more than 26,000 worth of email credentials. Dubbed CloudFanta, the malware has been targeting users mostly in Brazil till now. It has also been sending emails from the victims email ID and also monitoring their online banking activities. &nbsp; The cyber criminals who have unleashed CloudFanta had [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1493,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[66],"class_list":["post-1319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-safety","tag-cloud-antivirus"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CloudFanta malware steals millions of users email credentials<\/title>\n<meta name=\"description\" content=\"Netskope Threat Research Labs discovered that CloudFanta Malware has stolen banking information via cloud storage apps. Stay protected now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CloudFanta malware steals millions of users email credentials\" \/>\n<meta property=\"og:description\" content=\"Netskope Threat Research Labs discovered that CloudFanta Malware has stolen banking information via cloud storage apps. Stay protected now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/\" \/>\n<meta property=\"og:site_name\" content=\"Comodo Antivirus Blogs | Anti-Virus Software Updates\" \/>\n<meta property=\"article:published_time\" content=\"2016-11-02T04:31:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-08T13:35:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"225\" \/>\n\t<meta property=\"og:image:height\" content=\"170\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"seo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"seo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/\",\"name\":\"CloudFanta malware steals millions of users email credentials\",\"isPartOf\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg\",\"datePublished\":\"2016-11-02T04:31:41+00:00\",\"dateModified\":\"2025-04-08T13:35:04+00:00\",\"author\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\"},\"description\":\"Netskope Threat Research Labs discovered that CloudFanta Malware has stolen banking information via cloud storage apps. Stay protected now!\",\"breadcrumb\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#primaryimage\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg\",\"contentUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg\",\"width\":225,\"height\":170,\"caption\":\"emotet banking malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/antivirus.comodo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CloudFanta Malware Bypasses Virtual Keyboard Security, Steals Banking Credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/\",\"name\":\"Comodo Antivirus Blogs | Anti-Virus Software Updates\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\",\"name\":\"seo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"caption\":\"seo\"},\"url\":\"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CloudFanta malware steals millions of users email credentials","description":"Netskope Threat Research Labs discovered that CloudFanta Malware has stolen banking information via cloud storage apps. Stay protected now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/","og_locale":"en_US","og_type":"article","og_title":"CloudFanta malware steals millions of users email credentials","og_description":"Netskope Threat Research Labs discovered that CloudFanta Malware has stolen banking information via cloud storage apps. Stay protected now!","og_url":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/","og_site_name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","article_published_time":"2016-11-02T04:31:41+00:00","article_modified_time":"2025-04-08T13:35:04+00:00","og_image":[{"width":225,"height":170,"url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg","type":"image\/jpeg"}],"author":"seo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"seo","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/","url":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/","name":"CloudFanta malware steals millions of users email credentials","isPartOf":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#primaryimage"},"image":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg","datePublished":"2016-11-02T04:31:41+00:00","dateModified":"2025-04-08T13:35:04+00:00","author":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462"},"description":"Netskope Threat Research Labs discovered that CloudFanta Malware has stolen banking information via cloud storage apps. Stay protected now!","breadcrumb":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#primaryimage","url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg","contentUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/11\/RF-10296_thb_12.jpg","width":225,"height":170,"caption":"emotet banking malware"},{"@type":"BreadcrumbList","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/cloudfanta-malware-steals-banking-credentials\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/antivirus.comodo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"CloudFanta Malware Bypasses Virtual Keyboard Security, Steals Banking Credentials"}]},{"@type":"WebSite","@id":"https:\/\/antivirus.comodo.com\/blog\/#website","url":"https:\/\/antivirus.comodo.com\/blog\/","name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462","name":"seo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","caption":"seo"},"url":"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/comments?post=1319"}],"version-history":[{"count":28,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1319\/revisions"}],"predecessor-version":[{"id":21341,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1319\/revisions\/21341"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media\/1493"}],"wp:attachment":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media?parent=1319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/categories?post=1319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/tags?post=1319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}