Backdoored Torrents Infect Movie, TV Fans with GoBot2 Malware
#1
Quote:TV show and movie fans are being targeted by a malicious campaign that distributes a GoBot2 backdoor variant via files downloaded from several South Korean and Chinese torrent sites.
 
The malware dubbed GoBotKR by the ESET researchers who discovered it is being disseminated as part of a campaign started back in May 2018, with hundreds of samples having already been detected on the compromised computers of users from South Korea, China, and Taiwan.
 
GoBotKR has been developed to specifically target South Korean fans and this is shown by the South Korea-specific evasion techniques added to the original GoBot2 backdoor.
 
The GoLang-based GoBotKR backdoor is built by customizing the GoBot2 malware publicly available since March 2017 and the features added using GoLang libraries get executed on compromised computers with the help of legitimate Windows binaries and "third-party utilities such as BitTorrent and uTorrent clients."

SOURCE: https://www.bleepingcomputer.com/news/se...2-malware/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Backdoored Torrents Infect Movie, TV Fans with GoBot2 Malware - by silversurfer - 08 July 19, 15:14

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AV-TEST - ATP test: defending against at...
ATP test: Keeping d...harlan4096 — 06:46
Sandboxie 1.17.7 / 5.72.7
Release v1.17.7 / ...harlan4096 — 18:20
TinyWall 3.5.1
TinyWall 3.5.1 ...harlan4096 — 15:17
Microsoft Edge Removes Master Password F...
Microsoft has remo...harlan4096 — 15:15
QOwnNotes
26.6.4 Added an o...Kool — 06:08

[-]
Birthdays
Today's Birthdays
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>