Threat Database Malware BONDUPDATER

BONDUPDATER

By GoldSparrow in Malware

BONDUPDATER is a Trojan that poses a real threat to the computer it infects. Its targets are high-profile corporations located in the Middle East. The BONDUPDATER was spread by a group called OilRig, which has been using not only BONDUPDATER to attack its targets but also other Trojans and malware such as ISMAgent, Helminth eGobble, QUADAGENT and others. Its most effective distribution method is via spam email messages that pretend to be sent by a trusted source and well-implemented social engineering tactics. BONDUPDATER uses two different codes, both using DNS tunneling.

The intensity of its attacks will depend on determined conditions. Malware researchers think that the first action of BONDUPDATER will be collect data. Then it will try to find a way to identify the victims and lastly it will use the collected data to execute malicious tasks such as identity fraud and online banking unauthorized transactions. BONDUPDATER can gain persistence on a PC if its controllers want it. BONDUPDATER is a threat that should be detected and removed as soon as the computer users suspect its presence. BONDUPDATER can be removed manually. However, due to a series of technical issues that can occur during the removal process, it is better to hand over this responsibility to an anti-malware program.

Trending

Most Viewed

Loading...