Duuzer ,targets South Korean organizations
researchers have discovered 'bad actors' using the backdoor Trojan called Düüzer to target organizations in South Korea and other countries.
According to Symantec, threat actors are using a data-stealing Trojan called Dwyzer to target organizations primarily based in South Korea. Malicious users are conducting targeted attacks against organizations by distributing the Dwyzer backdoor to gain full control of infected systems.
Duuzer allows attackers to collect system information, access local network files, change file timestamps, upload and download files, and of course, execute commands.
According to Symantec researchers, Backdoor.Duuzer appeared around July 20, 2015, and attackers rely on spear phishing messages and watering hole attacks to spread it.
researchers have collected evidence that the malicious actors behind the Düüzer campaign have also spread two other malware programs, named W32.Brambul and Backdoor.Joanap. These two malware were also used to target organizations in South Korea and distribute additional payloads to infected computers.
According to Symantec, Dwyzer is directly linked to both malware, as every computer infected with Brambul was also infected with Dwyzer, and they share the same command and control (C&C) servers.
Duuzer is able to infect both [32-bit and 64-bit] systems, implements various methods to avoid detection, for example, it is able to check for the presence of virtual machines and also renames the malware with the name of an existing legitimate software that runs at startup.
[alert]In order to avoid infection by Duuzer, we recommend that you:
- Change the default credentials.
- Use string passwords.
- Keep your operating system and software updated.
- Do not open suspicious emails.
- Keep your security software up-to-date with the latest updates. [/alert]

