HomeSecurityExtensive cyber campaign targets US and Japanese organizations

Extensive cyber campaign targets US and Japanese organizations

Info-Stealer-Trojan-Nemim-Used-Against-Organizations-from-the-US-and-Japan-391292-2

Symantec security researchers have identified an extensive cyber campaign using the sophisticated Trojan Infostealer.Nemim.

The trojan is used to steal account login details for applications such as Outlook, Windows Mail, Gmail Notifier, Google Talk, MSN Messenger, Google Desktop, Internet Explorer, Firefox and Chrome.

Infostealer's main targets are located in the United States and Japan. However, infections have also been detected in India and the United Kingdom.

The threat has three components: an infector, a downloader, and an information stealer. The infector's operation is not complicated, it simply decrypts and runs an embedded file that represents the Downloader component.

The Downloader also acts as a wrapper for an encrypted executable file, which is dynamically loaded after it has been decrypted. This executable file is responsible for retrieving the Information stealer.

However, before the item is retrieved, a large amount of information is collected from the infected computer, such as the PC name, username, CPU name, operating system version, number of USB devices, IP address, and MAC address. The information is encrypted and sent to the command and control server (C&C Server).

Researchers believe that behind the Infostealer.Nemim Trojan is the same criminal group that has been targeting South Korean with the help of the Egobot Trojan since 2009.

Researchers have identified several similarities between Egobot and Nemim, such as the code injection technique they use, the form of communication with the C&C, encryption, and the way in which information is collected.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS