HomeSecurityThe Ramnit malware continues its activities

The Ramnit malware continues its activities

Ramnit

New information has emerged about Ramnit, a worm that now targets financial data. Among other things, a new feature has been reported that can disable Windows protection.

Ramnit has created a large network of infected computers that was recently disrupted by a joint operation between Europol and Symantec, AnubisNetworks and Microsoft's security division.

The number of computers at risk is estimated at 350,000, according to Symantec, while Microsoft telemetry data shows that more than half a million systems have been infected in the last six months.

The software started its activity in April 2010 as a worm-type virus that targeted EXE, SCR, DLL and HTML files. Since then it has evolved into malware that targets financial data and applications, when the code of the Trojan for the Zeus banking system was released online.

In their research, Microsoft researchers observed that Ramnit was based on two C & C servers. One of them was connected via DGA (domain generation algorithm) and was used to deliver various components, as well as to provide remote access to the machine.

The second has the address inside the configuration file and its purpose is to engage in stealing credentials for electronic banking transactions.

The big problem is that everything looks legitimate to the user, given that the content appears to come from the bank's own servers, and therefore it does not raise any suspicion in the victim.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS