US Under Attack from Virobot Ransomware with Botnet and Keylogger Traits
#1
Quote:The Virobot ransomware has been spotted making rounds in the United States on September 17, and it propagates itself via Microsoft Outlook spam e-mails. 

At the moment, Virobot's command-and-control (C&C) server has been shut down, and the malware will not be able to successfully encrypt infected systems until the threat actors who designed it will switch to a new one.
As reported by Trend Micro's Macky Cruz, the Virobot ransomware also comes with botnet capabilities meant to spread it between computers via a spam e-mail attack vector that uses Microsoft Outlook as transportation.

Virobot-infected e-mails are sent to the victim's entire Outlook contact list containing a copy of the malware or a link to a payload file which will be downloaded on the target machine when the spam message is opened.
After the ransomware infects a computer, it will do a quick registry check-up to find the machine's ProductID and GUID and, after generating a pair of encryption and decryption keys, it will send all the gathered info to its C&C server and start encryption the hard drive.

Source: https://news.softpedia.com/news/us-under...2839.shtml
[-] The following 2 users say Thank You to silversurfer for this post:
  • Dino101, harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
uBOLite 2026.529.1448 (already available...
uBOLite 2026.529.1...harlan4096 — 08:05
Microsoft Edge 148.0.3967.96
Version 148.0.3967...harlan4096 — 08:02
Brave 1.90.128 (Chromium 148.0.7778.217)
Release v1.90.128 ...harlan4096 — 08:01
Don’t let fake IPTV apps ruin your World...
We break down how ...harlan4096 — 07:59
Microsoft Rolls Out A New Update With Lo...
Microsoft has star...harlan4096 — 07:58

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>