Symantec has uncovered a sophisticated Trojan, Backdoor.Egobot, which steals confidential information from Korean companies and executives working with Korea (including targets from Australia, Russia, Brazil, and the United States) .
Attackers periodically send their victims a spear-phishing email with malware, which appears to come from someone they know (see screenshot). Once they download the payload, the Trojan can then do the following:
- Record video and audio snapshot
- Taking screenshots
- Upload files from a remote server
- Receive a recent list of documents
Symantec has uncovered another Trojan, Infostealer.Nemim, which appears to have originated from the same source as Backdoor.Egobot. A component of this Trojan can steal stored account information from multiple applications, including Internet Explorer, Mozilla Firefox, Google Chrome, and Microsoft Outlook. Japan and the United States are the primary targets of Nemim, followed by India and the United Kingdom.
More information is available here:
Source: techgear.gr

