HomeSecurityZemot Malware Dropper is distributed via Vogue.com subdomain

Zemot Malware Dropper is distributed via a Vogue.com subdomain

malware

High-profile domain names are in high demand by cybercriminals, who managed to compromise a subdomain of the vogue.com website and use it to distribute a variant of the Zemot malware downloader.

Zemot belongs to the Upatre family of malware droppers, which appears to have been exploited by the Asprox botnet around mid-September. The malware is used to drop additional malware onto a computer in order to perform specific tasks required by cybercriminals.

According to ThreatTrack Security, the request from Zemot came to media.vogue [dot] com, from machines infected with the infamous Gameover Zeus (GOZ).

Researchers say the GOZ sample detected is an updated version targeting financial institutions that has not been reported in previous malware.

This is not the first attempt to resurrect Gameover Zeus. In August, several security firms advised that the cybercriminals behind the malware were preparing to replace the botnet that went down in June.

Zemot wasn't the only malware being distributed through vogue.com, as there is evidence that the website was used to deliver another threat called Pony, also known as Fareit. This has InfoStealing capabilities but can also be used to add new malicious code to an infected machine.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS