New Worm.SymbOS.Lasco.a
Full article229 words · extracted from securelist.com · click to collapse
Analysis of the new virus mentioned in the previous posting showed that it’s a SymbianOS worm, based on Cabir source code, that spreads itself via BlueTooth. It also has a file infection functionality.
Upon execution, the virus searches for nearby BlueTooth devices (those which are in discoverable mode) and tries to transmit itself to any accessible ones. It also initiates a drive-wide scan for SIS-files and tries to infect them by inserting virus code directly into an SIS archive.
We’ve called this virus Worm.SymbOS.Lasco.a. An antivirus database update is already available.
A detailed description of the virus will be available in the Virus Encyclopedia in the near future.
UPDATE: the description of Lasco.a is now online.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-worm-symbos-lasco-a/29935/