HomeSecurityDo you use Skype? The T9000 is spying on your conversations!

Do you use Skype? The T9000 is spying on your conversations!

Skype

Security researchers are warning about a new backdoor trojan circulating the internet that is equipped with advanced file interception, screenshot , and Skype conversation recording capabilities.

 

The T9000 trojan is a hybrid version of the T5000 malware, which was first detected in 2013 and resurfaced in 2014, targeting automakers, human rights activists, and government agencies in the Asia-Pacific region.

The advanced variant, which was detected by researchers at Palo Alto Networks, is distributed through specially crafted spear phishing emails and primarily targets US businesses and organizations.

The T9000 is quite versatile and is designed to be used against any candidate target.

The malware is hidden in malicious RTF files, which exploit known vulnerabilities (CVE-2012-1856 and CVE-2015-1641) to compromise vulnerable systems.

Once installed on vulnerable computers, the malware collects information about the infected system and sends it to a C&C server. Based on this information, the server deploys special modules to the target computer.

Palo Alto researchers identified three main modules, which cause the most damage to affected devices.

The tyeu.dat , which is responsible for monitoring Skype users' conversations. Once the module is downloaded and executed, when Skype is launched, a message appears at the top of the window stating that "explorer.exe wants to use Skype."

Users who allow “explorer.exe” to interact with Skype are actually allowing the T9000 to spy on them.

The T9000 module can record text messages, audio and video conversations, and even take screenshots during video calls.

The T9000 has the ability to intercept other types of files, not just Skype chat data. Through the vnkd.dat , attackers can intercept data from storage devices with extensions such as doc, ppt, xls, docx, pptx, and xlsx.

Finally, the most harmless module is qhnj.dat, which allows the C&C server to send commands to infected computers, creating, deleting or moving files, and encrypting or copying data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS