Ukrainian and Russian police arrest banking Trojan masterminds
Written by v2r on April 9, 2013 – 12:30 am -Ukrainian newspaper Kommersant reported on a joint operation by the Ukrainian and Russian federal police arresting 20 people allegedly behind the Carberp banking malware. Is this a sign that we may see more arrests by the FSB and SBU in the future? Continue reading →...
READ MORE >>Tags: arrests, Banking Trojan, Carberp, computer security, Featured, FSB, Law & order, Malware, malware remove, Russia, SBU, ukraine, virus remove
Posted in Virus removal tools |
All Carberp botnet organizers arrested
Written by v2r on July 2, 2012 – 5:12 pm -We have been tracking the Carberp cybercrime group’s activity for three years now. Tracking started in 2009 with the first samples of the Carberp malcious software seen in the wild. By the beginning of 2010 the second wave of Carberp activity had forced out other banking malware families (Win32/Spy.Shiz, Win32/Hodprot) in Rus...
READ MORE >>Tags: Aleksandr Matrosov, Bank fraud, Blackhole, Botnet, Carberp, CARO, computer security, David Harley, Dmitry Volkov, ESET Russia, Facebook, Ilya Sachkov, malware remove, Nuclear Pack, smartcard exploit, virus remove, Win32/Carberp, Win32/Hodprot, Win32/RDPdoor
Posted in Virus removal tools |
Rovnix Reloaded: new step of evolution
Written by v2r on February 22, 2012 – 9:10 pm -[More research from our colleagues in Russia] In the beginning of February we found a new modification of our “old friend” Win32/Rovnix (the dropper detected as Win32/Rovnix.B trojan), which is the first bootkit using VBR (Volume Boot Record) infection. An interesting fact is that Rovnix bootkit components were used in ...
READ MORE >>Tags: Aleksandr Matrosov, Blackhole, bootkit, Carberp, CARO, computer security, David Harley, decryption, dropper, ESET North America, ESET Russia, Eugene Rodionov, FS, malware remove, Righard Zwienenberg, rootkit, Rovnix, Rovnix Reloaded, Russia, security software, space, TDL4, TDSS, Trojan, Trojan downloader, VBR, VFAT, virus remove, Win32 Carberp, Win32 Rovnix, Win32/Carberp
Posted in Virus removal tools |
Facebook Fakebook: New Trends in Carberp Activity
Written by v2r on January 26, 2012 – 5:33 pm -Aleksandr Matrosov, one of my colleagues in Moscow, writes: This month we discovered some new facts relating to Win32/Carberp trojan activity. We have spent a lot of time writing about Carberp already, but interesting information is still coming to light. The first interesting information to attract our attention recently concerned...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, Botnet, C&C, Carberp, computer security, David Harley, DDoS, Delphi, Facebook, Fake Facebook Lockout, fraud, Global Infection Statistics, information, malware remove, RBS, Russia, Russian Federation, statistics, virus remove, Win32 Carberp, Win32/Carberp
Posted in Virus removal tools |
Bootkit Threat Evolution in 2011
Written by v2r on January 3, 2012 – 9:42 am -The year 2011 could be referred to as a year of growth in complex threats. Over the course of this year we witnessed an increase in the number of threats targeting the Microsoft Windows 64-bit platform, and bootkits in particular. Here is a self-explanatory diagram depicting the evolution of bootkit threats over time: And no...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, Carberp, computer security, David Harley, Eugene Rodionov, information, malware remove, MBR, OS, rootkit, Rootkit Hidden Storage, Rovnix, security software, Senior Research Fellow, space, TDL4, TDSS, VBR, virus remove, Win32 Olmasco, Win32/Mebromi, Win32/Olmarik, x64, ZeroAccess
Posted in Virus removal tools |
2012 Predictions: East of Java
Written by v2r on December 12, 2011 – 11:28 pm -If you've been following this blog for a few years, you probably know that I'm reluctant to play the prediction game, but it seems to be expected at this time of year, so here's my contribution. Java will consolidate its position as the successor to PDF and SWF in the favourite exploits stakes, the latest Adobe problem ...
READ MORE >>Tags: 2012 predictions, Adobe, Aleksandr Matrosov, Black Hole, Carberp, computer security, David Harley, Dmitry Volkov, Eugene Rodionov, flash, Java, Malware, malware remove, Microsoft, Microsoft Security Report, Oracle, PDF, statistics, SWF, virus remove, vulnerabilities
Posted in Virus removal tools |
Carberp white paper: now with added pictures
Written by v2r on December 6, 2011 – 11:05 pm -After our latest blog on Carberp and the Black Hole exploit pack, we thought it would be useful to aggregate the material we've published to date on the topic into a single paper. That actually went up on the white papers page yesterday, but Aleksandr suggested adding some material that we thought would make it (even) more inte...
READ MORE >>Tags: Aleksandr Matrosov, Black Hole, Carberp, computer security, David Harley, Dmitry Volkov, Eugene Rodionov, Exploit, exploit kit, Group-IB, information, malware remove, RBS, remote banking systems, resources, Rovnix, SpyEye, Stop Digging, update, virus remove, white paper, white papers, Win32 Carberp
Posted in Virus removal tools |