Last year we saw how the Windows PowerShell® command shell was involved in spreading ROVNIX via malicious macro downloaders. Though the attack seen in November did not directly abuse the PowerShell feature, we’re now seeing the banking malware VAWTRAK abuse this Windows feature, while also employing malicious macros in Microsoft Word. The banking malware VAWTRAK is […]
Post from: Trendlabs Security Intelligence Blog – by Trend Micro
Banking Malware VAWTRAK Now Uses Malicious Macros, Abuses Windows PowerShell