TECH
Virus Ramnit already controls more than 100 thousand devices
There is a massive new Ramnit malware campaign, which has infected more than 100,000 devices. The warning is from Check Point which advises users and companies to take precautions against this possible large-scale attack from the creators of the virus.Ramnit belongs to the "class" of the worm, it affects the Windows operating system and is not detectable by antivirus. It was first identified in 2011. This malware is a sophisticated tool with functions of a rootkit, and happens by insertion via the internet and by the use of encrypted communications.Monitoring web browsing of the infected system and detecting visits to online banking pages; manipulation of web pages of banks in order to appear legitimate; theft of browser session cookies in order to replace the victim on secure sites; monitoring computer hard drives, as well as stealing passwords; and remotely accessing the affected computers are some of the criminal activities in which it has already been used.The Ramnit trojan makes the infected devices operate as a highly centralized botnet, even if its architecture involves a split in other independent networks, explains Checkpoint.Recently, a Ramnit server was found that is not related to the "Demetra" botnet that was most commonly used by the worm. According to the domain names in which the IP address of the server is resolved, the server will also control old bots that were first detected in 2015.This server has been active since March 6, 2018 but had not called attention until in May and July it infected about 100 thousand computers.
which in May and July infected about 100,000 computers.
Check Point has already detected signals from Ngioweb embedded in Ramnit in binary attacks that were probably spread as spam campaigns. However, Ngioweb is distributed primarily through the "Black" botnet.
The cyber security company analysts present a complete malware scan on their blog(https://tabuadigital.us16.list-manage.com/track/click?u=96e15dfa94b2c8db412be988f&id=ee94c938b9&e=9d48c4229a).
Sapo
 
 
No comments:
Post a Comment