ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Malware Miscellany, December 2007

highMalwareimportance 42
Full article332 words · extracted from securelist.com · click to collapse

Malware reports

Malware reports

22 Jan 2008

minute read

  1. Greediest Trojan targeting banks. Last month the winner of this title was Trojan.Win32.Qhost.sx, which targeted the customers of 42 banks.
  2. Greediest Trojan targeting payment systems. Trojan-Spy.Win32.Banker.bdn has its sights set on three payment systems at once.
  3. Greediest Trojan targeting payment cards.The winner of this category in December was Trojan-Spy.Win32.Banbra.vf.
  4. Stealthiest malicious program. Backdoor.Win32.Hupigon.rc is packed with 11 different packers, earning the title of December’s stealthiest program.
  5. Smallest malicious program. Trojan.BAT.KillFiles.gm took the lead in this category in the first month of winter – weighing in at all of just 12 bytes, it can nevertheless wipe the C: drive clean.
  6. Largest malicious program. The largest malicious program in December wasn’t so large after all – Backdoor.Win32.Bifrose.adr weighs in at just 85MB, which is noticeably smaller than previous winners of this category.
  7. Most malicious program. December’s most malicious program, Backdoor.Win32.Hupigon.vqe, deletes security software from memory, the hard drive and the registry.
  8. Most common malicious program in mail traffic. Once again, old-timer Email-Worm.Win32.Netsky.q wins this category, making up a hefty 20.03% of all malicious code in mail traffic in December.
  9. Most common Trojan family. Backdoor.Win32.Rbot took this title last month with 673 modifications.
  10. Most common virus/worm family. Another repeat offender, Email-Worm.Win32.Zhelatin has made its way back to the top, winning this title in December with 69 new modifications.
Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/malware-miscellany-december-2007/30394/