Shylock was a modular Windows banking Trojan first identified around 2011. It targeted online-banking users with man-in-the-browser techniques, credential theft, and fraudulent session manipulation. Its name came from text associated with Shakespeare's The Merchant of Venice found in the malware.
How Shylock banking fraud worked
Shylock could inject itself into browser activity and wait until the victim visited a targeted financial site. The user might be on the bank's genuine HTTPS domain while malicious code inside the compromised computer captured form data, altered content, or inserted fraudulent prompts. This is why the browser padlock alone could not protect an infected endpoint.
- Initial infection: malicious links, compromised sites, exploit kits, or deceptive downloads delivered the Trojan.
- Persistence and control: the malware established itself and contacted command-and-control infrastructure.
- Target configuration: operators supplied rules for selected banks, regions, or online services.
- Browser interception: web injects and form grabbing collected credentials or changed the session.
- Fraud: stolen access and manipulated transactions moved funds toward criminal accounts.
Some versions also included modules for additional data theft and remote functions. As with other modular banking Trojans, the visible family name may describe only part of the infection.
Shylock takedown and continuing relevance
Europol reports that the 2014 operation seized or redirected servers and domains supporting the Shylock botnet. At least 30,000 Windows computers were believed to have been infected, with strong targeting of UK users as well as victims in other countries.
The infrastructure disruption reduced the historical operation, but the techniques remain relevant. Modern banking malware still uses web injections, session theft, keylogging, overlays, and stolen browser data. The practical lesson is to verify financial activity through a clean channel, not to focus only on whether Shylock itself is still active.
Possible signs of a banking Trojan
- unexpected fields, delays, or security prompts appear only during a banking session;
- the bank reports a transfer, payee, device, or login the user does not recognize;
- a security alert identifies Shylock, a banker, web inject, form grabber, or credential stealer;
- the browser process creates unusual child processes or network connections;
- security tools are disabled or updates repeatedly fail;
- the user receives MFA prompts or account-recovery messages they did not initiate.
These symptoms are not proof of Shylock specifically. Preserve the complete detection and financial timeline instead of installing an old family-specific removal tool.
What to do after a Shylock or banking-Trojan alert
- Stop financial activity on the device. Disconnect it and do not use it to contact the bank or change passwords.
- Call the financial institution through a verified number. Report the suspected compromised session, review pending transfers and payees, and follow its fraud procedure.
- Use a clean device for account recovery. Reset email and banking credentials, revoke sessions, and update recovery information.
- Preserve evidence. Save alerts, suspicious messages, transaction identifiers, browser and endpoint logs, and the approximate infection time.
- Scan or rebuild the endpoint. Remove persistence and companion payloads. Reimage when integrity or privileged activity cannot be established.
- Review all affected accounts. Check reused passwords, business payment systems, cards, mailbox rules, and stored browser credentials.
Why changing only the bank password is insufficient
The Trojan may have captured email access, recovery information, session cookies, and passwords reused elsewhere. An attacker controlling email can reset financial accounts again. Secure the root identity accounts first, revoke sessions, and monitor transactions after restoration.
Frequently asked questions
Is Shylock the same as phishing?
No. Phishing can deliver a banking Trojan, but Shylock operated on the infected computer and could interfere with a real banking session.
Does HTTPS stop a man-in-the-browser attack?
HTTPS protects traffic between the browser and the bank. It cannot guarantee the browser process or operating system is clean before data is encrypted or after it is displayed.
Can an old Shylock sample still be dangerous?
Yes. Even if historical command servers are unavailable, executing archived malware is unsafe, and a detection may indicate other components. Quarantine and investigate it.