Emotet-Style Banking Trojan in Phishing Documents
Threat actors are exploiting the FIFA World Cup 2026 hype with fake ticketing sites, banking malware, and credential-harvesting campaigns, registering multiple scam domains that mimic official FIFA platforms. Banking trojans in this mold typically arrive as email attachments — a .docm document whose macro downloads the trojan, which then waits for the victim to visit a banking site before injecting fake login pages and stealing credentials and session tokens. Because trojans are continuously recompiled and obfuscated, single-engine detection is unreliable. This demo runs the EICAR test file, the industry-standard safe sample, inside a .docm container, so there is zero risk in handling it. Metascan aggregates 30+ anti-malware engines in a single scan, catching known banking trojan variants with multi-engine consensus while flagging suspicious macros for deeper inspection.
Attack Technique
Banking trojan
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗