Do you use Skype? A new trojan that has started circulating comes equipped with features that allow it to intercept files, take screenshots, and record Skype conversations.
The trojan, called T9000, is an evolution of the older version T5000, which was spotted online in 2013 and 2014. At the time, it targeted human rights activists, automakers, and governments in the Asia-Pacific region.
This time, Palo Alto Networks researchers report that the new T9000 was detected in US phishing emails, and that it is flexible enough to be used against any target an attacker wants to compromise.
The malware infects computers via malicious .RTF files that exploit the CVE-2012-1856 and CVE-2015-1641 vulnerabilities to enter the user's computer.
Compared to its previous version, T9000 is much more sophisticated. Security researchers who analyzed it say that the malware's developers have gone to great lengths to avoid detection by anti-viruses.
The T9000 features a multi-stage installation process, which checks before each phase for analysis tools from 24 security products, including: Sophos, INCAInternet, DoctorWeb, Baidu, Comodo, TrustPortAntivirus, GData, AVG, BitDefender, VirusChaser, McAfee, Panda, Trend Micro, Kingsoft, Norton, Micropoint, Filseclab, AhnLab, Jiangmin, Tencent, Avira, Kaspersky, Rising, and Qihoo 360.
This is how it evades detection. After its installation, the malware begins to collect the first information from the infected system and sends it to a C&C server (command and control server).
Once the infected computer is detected and registered on the C&C server, it will begin sending specific modules for each target, based on the information it has received. Palo Alto researchers identified three main modules.
The most important of these (tyeu.dat) is responsible for recording all Skype conversations. Once this module is downloaded to the infected computer, the next time the user starts Skype, a message will appear at the top of the window stating: “explorer.exe wants to use Skype.”.
The message appears because the trojan requests access to the Skype API. Users who agree to allow “explorer.exe” to interact with Skype are actually giving all the permissions that T9000 needs to spy on them.
The T9000 records audio conversations, videos, along with text chats, and also regularly takes screenshots of video calls.
The second module of T9000 (vnkd.dat), is loaded only when the attacker wants to steal files from the victim's computer. The module can steal files from the disk and from local removable storage devices with extensions such as doc, ppt, xls, docx, pptx, and xlsx.
The most “innocent” module is qhnj.dat, which is responsible for the infected computer's communication with the C&C server.
Those interested can read the full analysis on the Palo Alto website.
