Most media attention is given to imminent and visible threats, like ransomware. Other threats remain under the radar and often go unnoticed. Malicious proxies are one of these threats. The redirections done via malicious proxies are only activated in certain situations. Internet web browser settings are slightly modified, so that a very small (<1KB), and often obfuscated, proxy auto-config file is queried from the configuration server. If a victim browses particular websites, like banking sites, they are redirected to fake or malicious domains that pretty much look identical to real sites. Other than that, infected computers behave normally and victims usually don’t notice anything. All the credentials victims enter into fake sites are harvested by cybercriminals. This allows for a variety of attacks, including MitM and SSL impersonation, which may later lead to identity theft, unauthorized account access, and financial loss. In our talk, we will discuss the Retefe banking Trojan, which celebrated its comeback in the summer of 2016. There have been several changes made to Retefe, including, but not limited to, the structure of the delivered payload, geographical distribution, and the online banking systems it is targeting. Spread via malicious email attachments, a few malicious scripts are dropped and executed, and a rogue certificate is installed and the victim’s browser proxy configurations are changed. Retefe traditionally targeted banking users in German-speaking countries, however, we managed to detect completely new waves targeting banking users in the UK. The particular waves differ from one another, for example, Retefe started installing third-party tools and libraries (Tor, Proxifier,...), using different methods of persistence, and began targeting additional financial institutions. The last, and perhaps the most important part of the threat, are the mobile applications for Android, which the fake banking sites encourage victims to download. During our research we managed to collect and analyze hundreds of these apps. We will show a detailed infection vector, ways of targeting and changing settings of various web browsers, and reverse engineer all the malware components coming from the various waves, and finally show original and fake websites as they would be seen from clean and infected computers. We will also show the statistics and severity of this threat, as seen by our user base. We hope our talk will be beneficial for attendees coming from a DFIR background, because we intend to dive into all aspects of this threat, share interesting IOCs and system settings, which might be modified by Retefe or other similar malicious threats. Although Retefe is simple from a technical point of view, it is very powerful and efficient in reaching its hideous goals.