The Dridex botnet has been violated and distributes Avira Antivirus!

Part of the Dridex botnet distribution channel was infringed by an unknown Trojans replaced by Avira Antivirus installers!
white hat Dridex
The Dridex botnet remains an active threat, even after an attempt to remove it at the end of 2015.

Ο ς κώδικας που διανέμεται από το Dridex έρχεται συνήθως με τη μορφή spam μηνυμάτων που περιέχουν κακόβουλα συνημμένα αρχεία. Τα αρχεία που χρησιμοποιούνται συχνότερα, είναι τα έγγραφα του Word με ενσωματωμένες κακόβουλες μακροεντολές.

Once the victim opens the file, the macros download the malicious software from a remote server. Dridex creates a keylogger on infected computers, and using transparent redirects and webinjects manages to bypass codes from bank sites.

But the recent botnet hack was done for very different purposes.

“The malware's download URL has been replaced, with a link leading to an updated Avira antivirus installer," explained Moritz Kroll, Avira's malware expert.

So instead of malware, the victims download a valid, signed copy of Avira's protection software.

"We do not know exactly who did it and why - but we do have some theories," Kroll said.

A possible explanation is that someone White Hat managed to take over the botnet's control systems, and changed the malicious URLs to those of Avira.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).