Malware Miscellany, June 2007
Full article432 words · extracted from securelist.com · click to collapse
The middle of the month means it’s time for our miscellany, so let’s take a look at what the first month of summer brought us.
- Greediest Trojan targeting banks – this month the award goes to Trojan-Spy.Win32.Small.cz, which targeted 84 financial organizations. That’s just slightly less than last month’s 87.
- Greediest Trojan targeting payment systems – this title goes to Backdoor.Win32.VB.bck this month after it tracked the users of three different e-currency systems.
- Greediest Trojan targeting payment cards – Trojan-PSW.Win32.VB.kq, which took the same title in May, is really getting into its gluttonous stride. A new variant was detected in June which already targeting five different card systems, up from four last month.
- Stealthiest malicious program – in June this title went to Backdoor.Win32.Amutius.143, packed eight times using a range of packers.
- Smallest malicious program – this month we have the tiny 14-byte Trojan.BAT.DelTree.d. This puny program still packs a punch by deleting all directories from the disk.
- Largest malicious program – Trojan-Spy.Win32Banbra.ha weighed in as the month’s largest malicious program at nearly 30MB (almost nothing compared to last month’s whopper).
- Most malicious program – the leader in this category this month is Trojan.Win32.AddUser.k, which deletes antivirus solutions and services from the disk, from RAM, and all related registry keys.
- Most common malicious program in email traffic – the prize for this category goes to Email-Worm.Win32.NetSky.q, which accounted for over 16% of all malicious email traffic.
- Most common Trojan family – Trojan-Downloader.Win32.Agent is well ahead in this category, with 501 new variants detected in June.
- Most common virus/ worm family – Zhelatin put in some effort this month, with a total of 49 modifications being intercepted in June.
With so many Trojan variants, virus writers are showing no signs of taking off for the beach. Which means, of course, that we won’t either. Drop by the blog this time next month for an update.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/malware-miscellany-june-2007/30351/