ZeroHour
Cisco Talospublished ()ingested

SubSeven is back after hiatus

highMalwareimportance 42
Full article108 words · extracted from blog.talosintelligence.com · click to collapse

Monday, August 24, 2009 13:42

According to an entry on July 31, 2009 on www.subseven.org, the infamous backdoor SubSeven is back. "Work with the crew on a new version of 2.2 has begun. For now we will call it 2.3", said mobman, who is known for having written the first version of the program in 1999. There is no mention as to why development resumed after a break of several years. We grabbed a copy of the latest build (2.1.5) posted on the website and ClamAV detected the server and client files as:

server.exe: Trojan.SubSeven.215-srv
SubSeven.exe: Trojan.Spy-50523

We will continue to monitor this website for updates to SubSeven.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/subseven-is-back-after-hiatus/