BKDR_POISON: More Challenges Ahead

Last year, the security industry was plagued by a series of APT reports, which included the “Nitro Attack”. The backdoor used here is known as PoisonIvy or BKDR_POISON. Its builder is available online. Security vendors have then taken measures to counter this threat to help customers battle against similar infections in the future. However, [...]

NGOs Targeted with Backdoors

We have found evidence that the human rights organization found affected by a website compromise is not the only intended target for the attack. The website was said to have an iframe that redirected users to another compromised site in Brazil. The site executed a malicious Java applet detected as JAVA_DLOAD.ZZC. JAVA_DLOAD.ZZC leverages a [...]

Adobe Zero-day Vulnerability Installs Backdoor – Another Targeted Attack?

When I read this blog entry a few days ago, the first question that entered my head was, “Is this another targeted attack?”. I took a look at the .PDF discussed in the entry and it appeared to be a document addressed to employees of a certain defense contractor. Trend Micro products detect this [...]

Backdoor Snoops on Skype, MSN, and Yahoo! Messenger

We recently came across reports about a hacker group that was able to detect a backdoor which was found capable of monitoring online activities and recording calls when using Skype. However, apart from its routines, it garnered media attention because of its claims that the discovered backdoor may be used by German Law Enforcement. The [...]

Android Malware Uses Blog Posts as C&C

Newer and more complicated Android malware is expected along with the rising number of malicious Android applications, and a new backdoor that we were able to analyze proves that malware for the Android platform is continuously improving in performance, using new techniques to thwart analysis, and avoid detection. This Android malware, which Trend Micro detects [...]