In May 2019, Wapack Labs performed an inventory of recent Mirai specimens on Virus Total. A total of 29K malware specimens were observed during the period spanning from early March to mid-May 2019. A comprehensive indicator list is provided as a companion document to this product.
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
Showing posts with label Bot. Show all posts
Showing posts with label Bot. Show all posts
Thursday, May 23, 2019
Friday, July 14, 2017
Petya/NotPetya and Really Not Petya - Loki Bot Credential Stealing Malware
In late June 2017, Wapack Labs identified a malicious email targeting Ukrainian Financial Institutions (FI) to deliver a credential stealing malware called Loki Bot. This incident happened at the same time as the Petya/NotPetya Ransomware outbreak, which also targeted Ukrainian banking infrastructure. Possibly due to the confusion generated during the initial Petya/NotPetya outbreak, Loki Bot samples and C2s were reported as being Petya/NotPetya ransomware. Further confusion resulted when Anti-virus (AV) detections began identifying Loki Bot as Petya/NotPetya. Loki Bot is sold in underground Tor marketplaces and can steal passwords from browsers, File Transfer Protocol (FTP) applications, email accounts, and crypto-coin wallets. This report discusses the misattribution of Loki Bot, along with technical details of analyzed Loki Bot samples…Get the full report here.
Wapack Labs has cataloged and reported extensively on Loki Bot, and Loki RAT, in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
Labels:
Bot,
financial institutions,
Loki,
malware,
NotPetya,
Petya,
ransomware,
RAT,
TOR,
Ukraine
Subscribe to:
Posts (Atom)
