Troj/Bancos-LN is a password stealing Trojan aimed at customers of Brazilian banks.

Troj/Bancos-LN will monitor a user's internet access. When certain internet banking sites are visited, the Trojan will display a fake login screen in order to trick the user into inputting their details. In particular, the following domains are targeted:

Troj/Bancos-LN will then send the stolen details to a Brazilian email address.

When first run, Troj/Bancos-LN will copy itself to the Windows folder as KERNN.EXE. In order to run automatically each time a user logs in, Troj/Bancos-LN will set the following registry entry:


When triggered by visits to banking web sites, Troj/Bancos-LN will download a number of banking related images and SWF files to folders named BINM, CINM, RINM, BANESINM, SANINM in the Windows folder.