Incidents

The Rush for Windows 10 Infects PCs with Spy Trojan

Due to the high demand for Windows 10, Microsoft is releasing it gradually. This especially applies to certain countries. The official Microsoft Brazil website confirms it (left image). Cybercriminals from Brazil have taken advantage of this and are running a spam campaign identical to the official design offering a fake option for users to “get your copy now”. (right image)

win_1

When the victim clicks on “Instalador Windows 10” (Windows 10 Installer), it downloads to the system encoded VBE script:

win_2
win_3

This is a base64 encoded script, using legit Motobit software for encoding:

win_4

Once running, it drops the main trojan-spy component into the system. They also use funny Brazilian portuguese slang right inside of the code.

win_5

The dropped main banker module contains functionality to steal data from keystrokes and the clipboard. Additionally, it has backdoor capabilities for remote sessions and several anti-VM, debugging techniques.

Kaspersky Anti-Virus detects the initial VBE script as Trojan-Downloader.VBS.Agent.aok

Recently we noticed a big increase of VBS/VBE malware in Brazil, my colleague Fabio Assolini is working on a blogpost about a VBE malware widely spread in Brazil now.

The Rush for Windows 10 Infects PCs with Spy Trojan

Your email address will not be published. Required fields are marked *

 

  1. IVAN AREVALO

    Hola Dmitry. Soy Ivan, cliente de Kaspersky desde 2009. Me dirijo a usted en espanol, por que lei que usted radica en Ecuador. Tengo un problema con mi laptop despues del cambio que le hice a Windows 10. Ayer le instale el antivirus( el Kaspersky) que se habia desaparecido cuando baje el nuevo Windous 10 y ahora no puedo entrar a internet. Le he hecho todo lo que pide y no ha sido posible que me conecte a internet. Usted me puede ayudar para contartarme con un representante en la ciudad de Miami USA, donde radico?

    Espero su pronta respuesta por esta via. Agradezco su atencion.

    es muy urgente

    1. Dmitry Bestuzhev

      Hola Iván. Muchas gracias por su comentario. Por favor, contacte nuestro soporte técnico que también de hecho está en Miami http://latam.kaspersky.com/soporte

      Nuevamente gracias por su comentario y cualquier cosa, a sus órdenes.

  2. samuel Gill

    How do we check for this malware on our laptop if we live in Brasil?

    1. Dmitry Bestuzhev

      The easiest is to install a trial version of Kaspersky and to run a full system scan. If it’s not possible, please consider using AVPTool which is a detect and repair tool only with no real time protection.

      Thank you.

  3. Valerie

    Thank you for keeping us up to date. 🙂

  4. Henry

    Hello Mr. Bestuzhev,

    As many others have commented elsewhere, many consider Windows 10 itself to be spyware. So reserve Windows 10 (+) for mostly offline use, and switch to a different OS for online use.

Reports

Sunburst backdoor – code overlaps with Kazuar

While looking at the Sunburst backdoor, we discovered several features that overlap with a previously identified backdoor known as Kazuar. Our observations shows that Kazuar was used together with Turla tools during multiple breaches in past years.

Lazarus covets COVID-19-related intelligence

As the COVID-19 crisis grinds on, some threat actors are trying to speed up vaccine development by any means available. We have found evidence that the Lazarus group is going after intelligence that could help these efforts by attacking entities related to COVID-19 research.

Sunburst: connecting the dots in the DNS requests

We matched private and public DNS data for the SUNBURST-malware root C2 domain with the CNAME records, to identify who was targeted for further exploitation. In total, we analyzed 1722 DNS records, leading to 1026 unique target name parts and 964 unique UIDs.

What did DeathStalker hide between two ferns?

While tracking DeathStalker’s Powersing-based activities in May 2020, we detected a previously unknown implant that leveraged DNS over HTTPS as a C2 channel, as well as parts of its delivery chain. We named this new malware “PowerPepper”.

Subscribe to our weekly e-mails

The hottest research right in your inbox