Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Chthonic was a Zeus-derived Windows banking Trojan documented by Kaspersky in 2014. Its operators targeted customers’ computers and browsers—not bank infrastructure directly—and used web-page manipulation to steal banking credentials or help initiate transactions. Kaspersky’s configuration analysis found potential targets at more than 150 banks and 20 payment systems across 15 countries.

What Chthonic was

Kaspersky researchers Yury Namestnikov, Vladimir Kuskov, and Oleg Kupreev described Chthonic as a new modification of the Zeus banking Trojan, discovered in fall 2014. Zeus was the malware family it descended from; Chthonic was a distinct variant with its own modules and banking configurations.

The scale figures describe the targets listed in the configurations Kaspersky analyzed. They do not establish that every listed bank was actively compromised, or that the banks themselves were breached. The campaign aimed to infect customers’ Windows computers and interfere with banking sessions in their browsers.

Which countries and financial services were targeted

Kaspersky reported potential targets in 15 countries, covering more than 150 banks and 20 payment systems. It identified the following six countries as having the heaviest target concentrations; it did not provide a per-country count in the findings summarized here.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • United Kingdom
  • Spain
  • United States
  • Russia
  • Japan
  • Italy

The configuration analysis establishes the breadth of the targeting, not a complete list of named institutions or a count of victims in each country.

How Chthonic infected computers

Malicious links and email attachments

Kaspersky documented malicious links and email attachments as delivery routes. A user who opened a harmful link or attachment could expose a Windows computer to the Trojan; the campaign did not require the victim to visit a bank site first.

A crafted RTF exploiting Microsoft Office

One documented attachment was a specially crafted Rich Text Format (RTF) document that could exploit Microsoft Office vulnerability CVE-2014-1761 to execute code remotely. Microsoft had fixed that flaw in April 2014. This is a historical account of Chthonic’s delivery method, not evidence that the vulnerability remains exploitable on a fully updated Office installation today.

What Chthonic could do after infection

Kaspersky described modules that could collect information about the infected system, steal saved passwords, and record keystrokes. The malware could also provide attackers with remote access and record video or sound using available camera and microphone hardware.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For banking theft, its central technique was a web injection: inserting code or images into pages displayed in the browser. That could make a genuine banking page behave differently or replace what the customer saw, allowing attackers to request credentials or transaction-authentication details.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the banking-page attacks worked

Documented scenario What the browser showed or did Potential consequence
Japan Injected scripts hid bank warnings. The altered page could enable attackers to initiate transactions.
Russia The Trojan created an iframe displaying a convincing phishing copy of the bank’s site in place of the visible page. The fake page could prompt customers to enter credentials or transaction-authentication data.

Because the manipulation occurred within the browser, a page that looked familiar was not necessarily trustworthy on an infected computer. The examples illustrate why a password alone may not protect an account if the malware can also interfere with the transaction or solicit authentication information.

How to reduce the risk and respond to suspected theft

Before an incident

  • Keep Windows and Microsoft Office updated so security fixes are installed promptly, including fixes for vulnerabilities such as CVE-2014-1761.
  • Treat unsolicited links and attachments cautiously, especially unexpected Office documents. Verify the sender through a separate, trusted channel before opening an unexpected file.
  • Use reputable endpoint protection and keep it enabled and updated. Do not assume that a current security product detects Chthonic specifically unless its vendor documents that coverage.

If banking credentials may have been exposed

  1. Stop using the potentially infected computer for banking. From a separate, trusted device, contact the bank using its official app, website address, or the number on your card.
  2. Ask the bank to review recent activity and advise whether it should secure the account, block transactions, or replace credentials. Report any transaction you do not recognize promptly.
  3. Change affected passwords from the trusted device, starting with the bank account and any other account that reused the same password. Follow the bank’s instructions for resetting or re-enrolling transaction authentication.
  4. Have the Windows computer scanned and cleaned with reputable security software, or seek qualified technical help. Do not return to banking on it until you have confidence the infection is removed; if that cannot be established, use a trusted replacement device.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.