Banking trojan
termsecurity
Malware built specifically to steal money from online banking sessions - by capturing credentials, injecting fake fields into the bank's page, drawing a convincing overlay window on top of the real application, or altering payment details as a transfer is submitted.
The Brazilian variant is a distinct lineage with its own techniques, driven by local payment instruments: overlay attacks against desktop banking, and manipulation of the boleto, the printed payment slip whose barcode can be rewritten so the money goes elsewhere. Instant payments changed the target rather than removing it - fraud moved to social engineering the victim into authorising the transfer themselves. The defence that actually works is out-of-band confirmation of the destination, not detection of the malware.
Also known as: bancos, overlay attack, boleto malware, web inject