The DePriMon malware is a newly uncovered downloader, which is likely the creation of a hacking group called The Lamberts (also known as Longhorn). Experts were lead to believe that the DePriMon downloader belongs to The Lamberts group because the threat would often be used in combination with a malware family that belongs to the group, and is called ColoredLambert. There are several hacking tools that belong to the ColoredLambert family – Black Lambert, White Lambert, Blue Lambert, Green Lambert, Pink Lambert, and Grey Lambert.
About The Lambert Hacking Group
The Lambert hacking group is believed to have begun operating back in 2008, but its unsafe activity did not become public until 2014. They are considered to be a very experienced hacking group with a long history of devastating cyber-attacks launched against various high-profile targets. The Lamberts group seems to concentrate most of its efforts in Europe and the Middle East. The hacking group tends to go after corporations operating in the automotive, telecommunications, and aviation industries, among other high-profile lines of business. They also are known for targeting various government institutions.
The DePriMon malware has impressive abilities when it comes to remaining undetected and gaining persistence on the compromised machine. This new threat's name is based on how the malware masks itself on the infected host – Windows Default Print Monitor. Giving a threat such a generic name makes it much more difficult for the users to spot anything wrong with their systems. The DePriMon downloader works filelessly. This means that the threat operates from the memory directly, and its presence on the system is hidden with the help of reflective DLL techniques. Since the DePriMon downloader does not store its files on the disk of the infected computer, the traces of its harmful activity left on the system are reduced greatly. This makes it more difficult for anti-virus tools to detect the traces.
The DePriMon downloader is an impressive threat certainly, and The Lambert group is likely to continue using it in future campaigns.
Do You Suspect Your PC May Be Infected with DePriMon & Other Threats? Scan Your PC with SpyHunterSpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like DePriMon as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Security Doesn't Let You Download SpyHunter or Access the Internet?Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
- Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
- Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
- Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
- IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.