
T9000 Malware Backdoor Targets Skype Users and Records Their Conversations
Skype users should be wary of a new backdoor Trojan that steals files, takes screengrabs, and records conversations. The malware, dubbed T9000, is a hybrid version of an older one, T5000, that was discovered two years ago. T9000 targets human rights activists, the automotive industry, and governments in the Asia-Pacific region.
Security researchers at Palo Alto Networks have detected T9000 in phishing emails received by U.S. organizations. However, the researchers say T9000 is flexible enough to be used against any target an attacker wants to compromise.
Researchers noted that T9000 targets computers via a malicious RTF attachment in an email. This RTF attachment exploits the CVE-2012-1856 and CVE-2015-1641 vulnerabilities to gain a foothold on the victim's computer.
Compared to its previous version, T9000 is very complex and special efforts have been made to avoid detection. T9000 features a multi-stage installation process, which for analysis tools and 24 security products that check before each phase for the presence of Malware, such as Sophos, INCAInternet, DoctorWeb, Baidu, Comodo, TrustPortAntivirus, GData, AVG, BitDefender, VirusChaser, McAfee, Panda, Trend Micro, Kingsoft, Norton, Micropoint, Filseclab, AhnLab, Jiangmin, Tencent, Avira, Kaspersky, Rising, and Qihoo 360.
If everything checks out, and the internal checks pass, after installing itself, the Malware first collects information about the infected system and sends it to a C&C server, so that it can mark the target and distinguish it among each victim. The server will send a specific set of instructions based on the information present on the victim's computer.
Palo Alto researchers showed that the author of the malware seems like a true professional, “The creator of this backdoor has gone to great lengths to avoid detection and control by malware protection.”
