ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

New Cabir variant

highMalwareimportance 42
Full article211 words · extracted from securelist.com · click to collapse

Incidents

Incidents

24 Dec 2004

minute read

We have just received two very similar Cabir variants, purportedly from the author. This person claims that he/she has the source code and can make new worms instead of only Cabir variants.

We are conducting a detailed analysis and complete testing: we will post details when this is complete. In the meantime, the author asserts that the new Cabir, (Cabir.e in our naming system) “don’t show any message, only install and auto-sent to anothers cellphones…”. Symbian users should be very careful and check back for additional information.

The original Cabir, btw, required user interaction twice before completing installation routines.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-cabir-variant/29921/