Malware targeted at Syrian activists can operate webcam, disable AntiVirus, keylog, steal passwords

 

A fake PDF purporting to contain information on “the formation of the leadership council of the Syrian revolution” is circulating. As the Electronic Frontier Foundation’s Eva Galperin and Morgan Marquis-Boire report, it’s bad news for people who install it.

The latest surveillance malware comes in the form of an extracting file which is made to look like a PDF if you have file extensions turned off. The PDF purports to be a document concerning the formation of the leadership council of the Syrian revolution and is delivered via Skype message from a known friend. The malware installs a remote administration tool called DarkComet RAT, which can capture webcam activity, disable the notification setting for certain antivirus programs, record key strokes, steal passwords, and more. It sends this data back to the same IP address in Syrian IP space that was used in several previous attacks, including the attacks reported by CNN in February, the Xtreme RAT Trojan EFF reported in March, and this sample from March 21st.

Syrian Internet users should be extremely cautious about clicking on suspicious-looking links, or downloading documents over Skype, even if the document purportedly comes from a friend.

henrygee tagged this post with: , , , , Read 169 articles by

Enter your email address: Delivered by FeedBurner
  • http://www.bancodonordeste.net Elusa

    the language you use in your posts are not so popular nor too difficult.http://www.bancodonordeste.net

    • henrygee

      I try to make it easy for all to understand.

  • http://www. TT

    I think Malware targeted at Syrian activists can operate webcam, disable AV, keylog, steal passwords | MikiGuru is a good blog post and you do a good job of writing very detailed. Tommie – http://www.ep2p4u.com

About Me

Henrygee

He is a Technology Enthusiast. His love for Technology and everything related inspires him to sharing this passion with you.

Subscribe by Email

Enter your email address:

Delivered by FeedBurner

Advertisement

Like us on facebook

Advert

Page optimized by WP Minify WordPress Plugin