The source code of the Njw0rm RAT (remote access Trojan) was leaked in May 2013 from a website hosting malware and is believed to have been used as a starting point by malicious developers to create new malware.
The Kjw0rm (v2.0 and v0.5x) and Sir DoOom that are currently circulating have many similarities to the Njw0rm RAT, also known as njrat.
Despite the fact that both malware are developed in Visual Basic Script and the prototype was built with AutoIt, there are similarities that cannot be ignored, such as the propagation method they use.
Michael Marcos, a researcher at Trend Micro, reports that all three malware infects the computer via removable devices and creates shortcut icons for regular folders that lead to the malware.
However, Sir DoOom itself creates a set of folders (videos, photos, movies, games, and DCIM) that lead to malicious executables. Kjw0rm, on the other hand, simply hides the folders present in the root of the removable storage device and creates links leading to them.
The evolution is evident in both Kjw0rm and Sir DoOom variants, as more information is available in the malware's dashboard. There is the ability to check installed security products (antivirus, firewall), .NET versions, as well as system information (CPU, GPU, product ID and operating system key)
The capabilities of malware have increased since they now include management software (close, uninstall, restart), run remote shell, download and execute files. In the case of Sir DoOom, the developers also added a complete Bitcoin miner.
Both Kjw0rm and Sir DoOom have built-in anti-analysis mechanisms that can detect virtual machines. When such an isolated environment is detected, the malware simply uninstalls and terminates its activity, making it more difficult for security researchers to detect.
Michael Marcos beware of any removable drives that come from suspicious or untrusted sources. Also, check for any shortcuts that appear to point to legitimate folders. This could be an indication of malicious activity on your computer.
Source: secnews.gr


