The Loziok trojan is used to "suck" confidential data from computers infected with it.
Researchers have uncovered an ongoing espionage campaign using custom-developed malware that has the ability to siphon confidential data from energy companies around the world.
Trojan.Laziok , as it has been dubbed, acts as a reconnaissance tool that extracts information from infected computers, such as machine name, installed software, RAM size, hard disk size, GPU details, CPU details, and installed antivirus software, according to researchers at security firm Symantec . The attackers then use this data to decide how to infect your computer with additional malware, including versions of Backdoor.Cyberat and Trojan.Zbot, which are tailored to the compromised computer.
“Detailed information allows the attacker to make critical decisions about how to proceed with the attack, or whether to stop the attack,” Symantec researcher Christian Tripputisaid. “During our research, we found that the majority of targets are associated with the oil, gas, and helium industries, suggesting that whoever is behind these attacks may have a strategic interest in the businesses of the companies being targeted.”
The United Arab Emirates was the country with the most targeted attacks, followed by Saudi Arabia, Pakistan and Kuwait.
Computers are initially infected with Laziok via spam emails originating from the moneytrans[.]eu domain. The emails contain a malicious attachment that exploits a Microsoft Windows vulnerability that was patched in 2012. The same vulnerability has been exploited in other espionage attack campaigns, including one that used the Red October malware platform to infect diplomatic, government, and scientific organizations in at least 39 countries.
Laziok usually comes in the form of an Excel.

