Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:50:04 UTC Home > List all groups > List all tools > List all groups using tool Karius Tool: Karius Names Karius Category Malware Type Banking trojan, Info stealer, Credential stealer Description (Check Point) The Check Point Research team recently came across one such banking Trojan under development and already being distributed through the RIG Exploit Kit. Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker. While Karius is not yet in full infection mode, initial tests have already been made and our research below shows the evolution of how such malware takes place. Our analysis also shows how banking trojans such as Karius are put together and makes use of code from other well-known bankers such as Ramnit, Vawtrak and TrickBot. Information Malpedia Last change to this tool card: 23 May 2020 Download this tool card in JSON format All groups using tool Karius Changed Name Country Observed Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028 Page 2 of 2 Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) Page 1 of 2