TorrentLocker: Crypto-ransomware still active, using same tactics

In December 2014, ESET released a white paper about TorrentLocker, a crypto-ransomware family spreading, via spam, email messages that impersonated local postal service, energy or telecom companies. The paper described its distribution scheme, its core functionalities, its network protocol and exposed some similarities with the Hesperbot banking trojan. During the last few months, we decided to … More TorrentLocker: Crypto-ransomware still active, using same tactics

First Twitter-controlled Android botnet discovered

Android/Twitoor is a backdoor capable of downloading other malware onto an infected device. It has been active for around one month. This malicious app can’t be found on any official Android app store – it probably spreads by SMS or via malicious URLs. It impersonates a porn player app or MMS application but without having … More First Twitter-controlled Android botnet discovered

Nemucod serves nasty package: Combining ransomware and ad-clickers

Nemucod, previously one of the worst infecting malware types in Ireland is causing mayhem again. Just last week ESET reported on Nemucod shifting away from ransomware and downloading the ad-clicking malware Kovter instead. Now, it seems that the operators of the notorious downloader went a step further and are serving their victims the whole package … More Nemucod serves nasty package: Combining ransomware and ad-clickers

Nemucod now spreading banking trojans

ESET researchers noticed a huge outbreak of a new Spy.Banker variant, detected as Spy.Banker.ADEA. Nemucod has previously been one of the most detected malwares in Ireland. On the morning of Friday August 12th, at around 12pm CET this new variant was spotted in Brazil. Similar to previous ones used by other banking trojans in South America, … More Nemucod now spreading banking trojans

Nemucod is back and serving an ad-clicking backdoor instead of ransomware

Nemucod, the Trojan that affected Ireland worst in 2016 is back with a new campaign. Instead of serving its victims ransomware, it delivers an ad-clicking backdoor Trojan detected by ESET as Win32/Kovter. As a backdoor, this trojan allows the attacker to control the machine remotely without the victim’s consent or knowledge. The currently used variant … More Nemucod is back and serving an ad-clicking backdoor instead of ransomware