Windows Activator Bundles Banker with C2 in YouTube Description

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,176
In their effort to hide the command and control (C2) server addresses, operators of a banking trojan placed them in fake websites and in descriptions for YouTube videos.
The name of the malware is Casbaneiro and its wide distribution is possible through ReLoader, an illegal activation tool to create pirated versions of the Windows operating system and Microsoft's Office suite.
Some variants of ReLoader download and install the banking trojan first and only then run their intended course.

ReLoaderActivator_ESET.jpg
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top