HomeinetSpread of Trojan Viknok, a Click-Fraud malware

Spread of Trojan Viknok, a Click-Fraud malware

Symantec warns of an outbreak of Trojan Viknok. Before the advent of Ransomware, click fraud was one of the most popular and effective ways for cybercriminals to make money.
“Click-Fraud” is the practice of collecting clicks on advertisements with the aim of increasing revenue for websites that use it.
According to Symantec, a new malware used by cybercriminals to collect clicks has emerged. Last month, the company’s researchers noticed an increase in infections with a malware called Trojan.Viknok.

viknok
Trojan.Viknok was first observed by security researchers in April 2013. Researchers understood that the malware was a sophisticated threat because it had the ability to turn victims’ computers into a botnet. To do this, the malware can gain administrator privileges on the operating system to infect system files on multiple Windows operating systems, such as 32- and 64-bit versions of Windows XP, Vista, and 7.
Viknok-infected computers were then used by cybercriminals to conduct ad-Click-Fraud.
“The crooks behind the current Viknok campaign are trying to add more and more victims to their AdClick botnet in order to earn more money,” Symantec’s report states.

How does Viknok infect computers?

Viknok is quite sophisticated as we mentioned above and infects victims' computers by injecting its payload into the system's DLL files. Cybercriminals use several methods to infect files, such as rpcss.dll, a library that runs every time Windows starts. So, once an attacker can infect the rpcss.dll file, the malicious code runs every time Windows starts.

«In many cases, the infection process is completely stealthy, the threat does not show any warning to the user. The malicious software is also difficult to detect, given that it does not present any suspicious process running, nor does it infect any of the system's critical points” say the researchers at Symantec in their blog.

When the malware starts running, the system's User Account Control (UAC) prompts the victim to grant the necessary permissions. If the user does not grant their permission, their system will not be infected. However, the malware disguises itself as a process that is native to the user in order to obtain their permission and gain the necessary permissions.
Once permission is granted by the system owner, the attacker can remotely send commands and load various websites. The websites offer car insurance, travel tickets, domain name registrations, and many other services.
The number of Viknok infections has increased dramatically over the past few months. From January to April, the number of unique infections increased from 10,000 to 22,000. Over 16,500 unique Viknok infections have been observed in the first week of May alone. The majority of victims are in the United States.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS