ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Sober.q has become active

highMalwareimportance 42
Full article208 words · extracted from securelist.com · click to collapse

Incidents

Incidents

15 May 2005

minute read

In the meantime Sober.q has become active, instead of sending copies it’s sending spam messages now.

This is quite the opposite from the message the Sober author included in his latest creation.

These spam messages link to right winged articles.

So in a way we’re seeing the same story as with Sober.g again.
Sober.g downloaded Sober.h, Sober.h in turn also sent out spam.

I can remember that the Netherlands were completely flooded by those emails back then, judging from the numbers that Sober.p generated just before it stopped it probably won’t be that much different this time.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/sober-q-has-become-active/30009/