Researchers at ESET have discovered a botnet dubbed “Georbot”, a new botnet that targets victims living in the Eurasian state of Georgia. The information stealing Trojan is unusual to a degree, researchers said, given some of its functions and location of its command and control (C&C) server.
After some digging, ESET researchers were able to access the C&C used by the bot, and discovered some interesting features. The Trojan will look for and copy documents and certificates, as well as create audio and video recordings. Moreover, it can browse the local network connection in order to discover more information. The data that is harvested is sent to the C&C for later collection.
“One unusual aspect is that it will also look for “Remote Desktop Configuration Files” that enables the people receiving these files to connect to the remote machines without using any exploit. That approach will even bypass the need for RDP exploits such as the one that was revealed last week (MS12-20),” ESET’s Righard Zwienenberg wrote.
The Trojan attempts to hide from AV detection, and it has a backup plan in case the main C&C is offline – it connects to an alternate C&C hosted on a Georgian government domain.
“This does not automatically mean that the Georgian government is involved. Quite often people are not aware their systems are compromised. It should be also noted that the Data Exchange Agency of the Ministry of Justice of Georgia and its national CERT were fully aware of the situation…,” Zwienenberg added. A report on the botnet is available online.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Critical Vulnerability Impacts Over 120 Lexmark Printers
- BIND Updates Patch High-Severity, Remotely Exploitable DoS Flaws
- Industry Reactions to Hive Ransomware Takedown: Feedback Friday
- Microsoft Urges Customers to Patch Exchange Servers
- Iranian APT Leaks Data From Saudi Arabia Government Under New Persona
- US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware
- Cyberattacks Target Websites of German Airports, Admin
- US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’
