A database of major known threats as seen by Webroot and other security channels.
Recently active
A network of private computers infected with malicious software and controlled as a group without the owners' knowledge, e.g., to send spam messages. Andromeda Nanobot Adwind
Spyware is software that aims to gather information about a person or organization sometimes without their knowledge, that may send such information to another entity without the consumer's consent, that asserts control over a device without the consumer's knowledge, or it may send such information to another entity with the consumer's consent, through cookies.Below are some of the known spyware variants: KEYMARBLE RANCOR Vermin HeroRAT InvisiMole SocketPlayer Joker
A Worm’s purpose is to propagate and spread as much as it can because it’s usually designed to find a specific environment as its target. It differs from a virus in that it doesn’t need a host file to infect and spread. Once the worm reaches its target environment it has limitless options of the end goal from the attacker, like deleting files or delivering other malware payloads like ransomware. Ransomware combined with worms using exploits was made famous with the WannaCry and NotPetya attacks in 2017 that caused over $5 Billion in damage. Below are some of the known worm variants: Brambul
Trojans are installed generally without a user’s full, meaningful, and informed consent. A Trojan differs from most malware as the payload (or the behavior) of a Trojan can be controlled potentially from a remote site. Trojan Dropper: A file that contains at least one additional, malicious file. For a file to be a Trojan Dropper and not solely a “dropper” its payload must be comprised of multiple, unrelated spies (multiple, unrelated spies indicate that this is a custom, affiliate installer). A Trojan Dropper may be an executable that contains multiple files. When the Trojan Dropper executes, the files inside the .exe are installed. A Trojan Dropper may also be a .chm (Windows Help File). Since a .chm is really a Windows proprietary compressor, it may contain multiple, malicious bundles inside the .chm, which the Trojan Dropper installs when the user exec Trojan Downloader: After installation, the Trojan contacts a remote host/site and installs packages or affiliates from the remote
The world of cryptocurrency is in its infancy stages, but criminals have been using it for years and proving the utility and anonymity of blockchain technology. Not to mention the spike in interest and speculative price on the technology has really put a focus for criminals to accumulate as much as possible. The ledger system required for blockchain tech requires mining as a fundamental. Criminals have found ways to leverage victims computers to be part of the mining operation. Victims computers will have their CPU stolen in order to mine the cryptocurrency to which the criminals will be directly rewarded without having to deal with victims for any payment scheme. It’s now grown so popular with the profitability along with minimal illegal footprint, that its one of top threats in the landscape today. Below are some of the known cryptominer variants: PowerGhost ZombieBoy msHelper WinstarNssmMiner ADB.Miner PyRoMinelot
Quite possibly the most devastating malware for victims and most profitable for criminals. This type of malware aims to block access to your data by either encrypting your files or the entire hard drive. To get your data back, victims are forced pay the criminals ransom to get their files back. Historically, ransom payments to cybercriminals was through Ukash and Moneypak, but with the emergence of cryptocurrency and the anonymity and versatility it offers, crypto is now the only payment criminals will take. There is no guarantee that victims will get their files back, but for the most part criminals do decrypt the files or else no one would pay the ransom. This is one of the most popular payloads of choice for criminals and it’s been featured in just about every type of attack vector like email attachments, exploit kits, browser extensions, office macros, Remote Desktop Protocol (RDP), ect. If a cybercriminal has breached your system the most likely end result will be ransomware. F
The oldest of all malware is the virus and it’s been around since the 70's. Designed to attach its code to other programs. Once those infected programs are executed, the virus will duplicate itself and spread like mad. Today, “Viruses” by their strict definition are rare in the wild and are usually in the form of file infectors. Below are some of the known virus variants: CEIDPageLock Dark Tequila Marap DeepLocker Dark Caracal Ramnit Rakhni OSX.Dummy PROPagate GZipDe MirageFox Zacinlo Olympic Destroyer Kardon Loader Mylobot Clipboard Hijacker MysteryBot DMOSK KillDisk BabaYaga The Nocturnal Stealer MalHide VPNFilter Vega Stealer LockerGoga
Keyloggers and System monitors are either commercial or non-commercial. A commercial system monitor is a piece of software with system monitor characteristics, obtained with a legitimate license by legal means. All other system monitors are non-commercial system monitors. The system monitor category encompasses any software that performs the following actions: Overtly or covertly records system processes and/or user actions Makes those records available for retrieval and review at a later time These processes can include any action on a machine from the time it turns on to the time it turns off, such as: Time of power on Login information E-mail passwords Financial account information Credit card numbers Social security numbers Screenshots Phone numbers Addresses Keystrokes Webcam photos Sound Time of power off Any other computer activity Example
Joker is Spyware and a premium subscription bot that was found on Google Play. It has been detected in 24 apps so far with over 472,000 installs. The name "the Joker" was borrowed from one of the C&C domain names. It silently simulates the interaction with advertisement sites, steals SMS messages, contacts, and device info. Google has already removed all of the apps listed in this article from Google Play and we have had these marked in our system since early last week. Article Link - Read moreGlossary Blog Back to the Malware Manifesto Use our free virus scanner to make sure your devices aren't affected or use our antivirus software to always stay protected.
Summary - Jokeroo is a RaaS or Ransomware-as-a-Service being sold on the Darkweb. This RaaS requires an up front member fee. This ranges from $90 - $600 which allows the purchaser to keep anywhere from 85% to 100% of profits and even extra items such as Salsa20 encryption. Jokeroo was initially promoting itself as GandCrab which was then later changed to Jokeroo. Glossary Blog Back to the Malware Manifesto
Summary - LockerGoga is a Ransomware variant that appears to be targeting European companies. The encryption process used by LockerGoga is slow, showing a lack of sophistication. LockerGoga was signed using a valid Digital Certificate which has since been revoked. Glossary Blog Back to the Malware Manifesto
Summary - Antova is Ransomware that encrypts files that are 1MB or smaller in size and will also encrypt files on connected network shares. This Ransomware appears to support additional modules which could be used to perform other malicious activities in addition to file encryption. Glossary Blog Back to the Malware Manifesto
Summary - Adwind RAT, first discovered in 2013, is a multi-platform Remote Access Trojan written in Java which is more commonly known as jRat. Adwind is provided as a malware-as-a-service for the attackers most commonly distributing it via malspam. When via a malspam email, a .jar attachment will be the payload. Adwinds capabilities range from collecting keystrokes, taking screen shots and viewing webcam to even stealing VPN certificates. Glossary Blog Back to the Malware Manifesto
Summary - Nanobot is a botnet with hosts controlled by the NanoCore RAT, a Remote Access Trojan that targets Windows operating system users. All versions of the RAT feature base plugins and functionalities such as screen capture, crypto currency mining, remote control of the desktop and webcam session theft. NanoCore is sold on dark web forums for approximately 25 USD, but various versions of the RAT were leaked over time. Glossary Blog Back to the Malware Manifesto
Summary - Andromeda, also known as Gamarue, is a modular botnet whose functionailities can be modified via plugins. Some of its functions include: keylogging, rootkit, teamviewer and spreader. Andromeda was spread many different ways such as malspam, trojan downloads and exploit kits. The primary goal of Andromeda was to distribute other malware families, on top of stealing personal information. In November 2017, in a joint operation, international law enforcement took down the Andromeda botnet by taking control of servers and domains used as C&Cs for the botnet. Glossary Blog Back to the Malware Manifesto
Summary - These are variants which you will typically see come in via compromised RDP accounts in bruteforce attacks. Crysis was first spotted some time in 2016. Due to similarities in code, Dharma is thought to be a product of Crysis. Crysis will usually demand a payment of around $1000-$1500, per machine. GlossaryBlogBack to the Malware Manifesto
Summary - Bitpaymer is a multi vector ransomware which has been seen in RDP scenarios as well as dropped by trojans, such as Trickbot. Bitpaymer is a unique ransomware in that it utilizes alternate data streams (ADS) to hide itself from antivirus. This essentially makes the ransomware file-less shortly after execution. Bitpaymer has been known to charge hefty ransoms, in the case of a London college, reaching 53 bitcoins. GlossaryBlogBack to the Malware Manifesto
29th August, 2018 By Charlie Osborne ZD Net Summary - The RIG exploit kit, which at its peak infected an average of 27,000 machines per day, has been grafted with a new tool designed to hijack browsing sessions. The malware in question, a rootkit called CEIDPageLock, has been distributed through the exploit kit in recent weeks. According to researchers from Check Point, the rootkit was first discovered in the wild several months ago. CEIDPageLock was detected when it attempted to tamper with a victim's browser. The malware was attempting to turn their homepage into 2345.com, a legitimate Chinese directory for weather forecasts, TV listings, and more. Article Link - Read more Glossary Blog Back to the Malware Manifesto
22nd August, 2018 By Pierluigi Paganini Security Affairs Summary - Security experts from Kaspersky Labs have spotted a sophisticated strain of banking malware dubbed Dark Tequila that was used to target customers of several Mexican financial institutions. According to the researchers, the complex Dark Tequila malware went undetected since at least 2013. Dark Tequila is a multistage malware that spreads via spear-phishing messages and infected USB devices. The malware steals financial data from a long list of online banking sites from infected systems, it is also able to gather credentials to popular websites, business and personal email addresses, domain registers, and file storage accounts. Article Link - Read more Glossary Blog Back to the Malware Manifesto
21st August, 2018 By Catalin Cimpanu Bleeping Computer Summary - A new ransomware strain named Ryuk is making the rounds, and, according to current reports, the group behind it has already made over $640,000 worth of Bitcoin. Attacks with this ransomware strain were first spotted last Monday, August 13, according to independent security researcher MalwareHunter, who first tweeted about this new threat. Article Link - Read more Glossary Blog Back to the Malware Manifesto
16th August, 2018 By Linday O'Donnell Threat Post Summary - A new downloader, which has been spotted in an array of recent email campaigns, uses anti-analysis techniques and calls in a system fingerprinting module. A newly discovered downloader malware has been discovered as part of a new campaign primarily targeting financial institutions. Researchers at Proofpoint said today that the downloader – dubbed “Marap” after its command-and-control phone-home parameter, “param,” spelled backwards – is notable for its focused functionality and modular nature, as well as its ability to perform reconnaissance through a systems-fingerprinting module. Article Link - Read more Glossary Blog Back to the Malware Manifesto
10th August, 2018 By Juha Saarinen IT News Summary - The United States Computer Emergency Readiness Team (US-CERT) has issued a fresh warning that a new piece of malware believed to be created by North Korean government actors is on the lose on networks around the world. Known as KEYMARBLE, the malware is a Remote Access Trojan (RAT), US-CERT said and cautioned users against opening attachments in emails, even when the sender appears to be known. The RAT is a 32-bit Windows executable that can access device configuration data, download further files, run commands, modify the Windows Registry configuration and settings database, take screenshots and exfiltrate data, according to the Malware Analysis Report (MAR) by US-CERT. Article Link - Read more Glossary Blog Back to the Malware Manifesto
8th August, 2018 By Nicky Cappella The Stack Summary - While DeepLocker has yet to be seen outside of the research lab, all of the tools used to create it are readily available: existing malware, and AI tools that can be trained to recognize a target. DeepLocker malware can remain undetected for lengthy periods, inactive until presented with an AI trigger – through facial or voice recognition, or geolocation – that indicates a specifically targeted individual. When the trigger is recognized, it acts as a key, activating the dormant malware on the system. Article Link - Read more Glossary Blog Back to the Malware Manifesto
6th August, 2018 By Nick Lewis TechTarget Summary - Dark Caracal is written in Java, so it can be used against any computer that executes Java code. It is an immature remote access tool that appears to be used by nation-state actors, but it only works on systems with Java installed -- so it shouldn't affect most systems running macOS 10.7 and later, as those versions no longer install the Java runtime by default. Article Link - Read more Glossary Blog Back to the Malware Manifesto
6th August, 2018 By Tara Seals Bleeping Computer Summary - A massive proxy botnet is just the tip of the iceberg, a warning sign of a bigger operation in the works by the Ramnit operators. The recently uncovered “Black” botnet campaign using the Ramnit malware racked up 100,000 infections in the two months through July– but the offensive could just be a precursor to a much larger attack coming down the pike, according to researchers, thanks to a second-stage malware called Ngioweb. Check Point Research said that the actors behind the Black botnet are mainly working on creating a network of malicious proxy servers; infected machines that together operate as a high-centralized botnet, “though its architecture implies division into independent botnets.” Article Link - Read more Glossary Blog Back to the Malware Manifesto
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.