Skip to main content
← Back to Demos
Malware beginner · 15 min

Emotet-Style Banking Trojan in Phishing Documents

Threat actors are exploiting the FIFA World Cup 2026 hype with fake ticketing sites, banking malware, and credential-harvesting campaigns, registering multiple scam domains that mimic official FIFA platforms. Banking trojans in this mold typically arrive as email attachments — a .docm document whose macro downloads the trojan, which then waits for the victim to visit a banking site before injecting fake login pages and stealing credentials and session tokens. Because trojans are continuously recompiled and obfuscated, single-engine detection is unreliable. This demo runs the EICAR test file, the industry-standard safe sample, inside a .docm container, so there is zero risk in handling it. Metascan aggregates 30+ anti-malware engines in a single scan, catching known banking trojan variants with multi-engine consensus while flagging suspicious macros for deeper inspection.

Attack Technique

Banking trojan

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---