ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Malware Miscellany, February 2008

highMalwareimportance 42
Full article324 words · extracted from securelist.com · click to collapse

Malware reports

Malware reports

18 Mar 2008

minute read

  1. Greediest Trojan targeting banks: This month’s nominee is Trojan-Spy.Win32.Banker.cjj, which targets 44 banks simultaneously.
  2. Greediest Trojan targeting payment systems: Trojan-Spy.Win32.Banker.iei has its sights set on the users of 4 different payment systems.
  3. Greediest Trojan targeting payment cards: This month’s winner, Trojan-Spy.Win32.Banker.ibp is slightly unusual – it targets users of 5 systems at once, rather than the more usual 3 or 4.
  4. Stealthiest malicious program: Trojan-Dropper.Win32.Small.to wins this category in February, being packed with 10 different packers.
  5. Smallest malicious program: In spite of its minute 27 byte size, Trojan.BAT.KillWin.cs have a very nasty payload: as its name suggests, it ‘kills’ the Windows operating system.
  6. Largest malicious program: Once again, a member of the Haradong family wins this category: Trojan.Win32.Haradong.ct weighs in at a heft 226MB.
  7. Most malicious program: February’s winner is one of the modifications of Backdoor.Win32.Agobot.gen. This unpleasant program disables a wide range of security solutions and also deletes files and processes.
  8. Most common malicious program in mail traffic: Email-Worm.Win32.Netsky.q puts in yet another appearance, making up almost 36% of all infected mail traffic in February.
  9. Most common Trojan family: Trojan-PSW.Win32.Onlinegames took the prize this month, with 1092 modifications.
  10. Most common virus/ worm family: Email-Worm.Win32.Warezov pops up again in this category with a relatively modest 30 modifications in February.
Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/malware-miscellany-february-2008/30406/