Header Ads

Symantec uncovers new sophisticated "Korean" Trojans

Egobot and Nemim

Symantec recently uncovered a sophisticated Trojan, Backdoor.Egobot, which steals confidential information from Korean companies and also executives doing business with Korea (including targets from Australia, Russia, Brazil, and the United States). More details after the jump.

The attackers will often send their victims a spear-phishing email containing malware that appears to be from someone they know (see screenshot above). Once the payload has been downloaded, the Trojan is able to do the following:

  • Record video and audio
  • Take screenshots
  • Upload files to a remote server
  • Obtain a recent document list

Symantec has also uncovered another Trojan, Infostealer.Nemim, which we believe originates from the same source as Backdoor.Egobot. A component of this Trojan can steal stored account credentials from many applications, including Internet Explorer, Mozilla Firefox, Google Chrome and Microsoft Outlook. Japan and the United States are the main targets of Nemim, followed by India and the United Kingdom.

More information can be found here:

Source: Symantec

Back to top

No comments:

Powered by Blogger.