Threat Database Trojans TSPY_ZBOT.YYKE

TSPY_ZBOT.YYKE

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 27
First Seen: April 10, 2014
Last Seen: February 21, 2022
OS(es) Affected: Windows

TSPY_ZBOT.YYKE is a variant of the ZeuS Trojan that has been associated with recent attacks involving the Upatre Trojan. This attack has been connected to spam email messages that contain threatening attachments and pretend to contain official messages from important banking institutions such as Lloyds or Wells Fargo. Corrupted spam email messages associated with TSPY_ZBOT.YYKE will try to convince the victim that their bank has sent a secure message to them. This supposed safe message is contained in a MSG file attached to the corrupted email message. Needless to say, the supposed 'message' is a threat.

The TSPY_ZBOT.YYKE is a Variant of the Infamous Upatre

The MSG file contains another MSG file which itself contains the Upatre Trojan variant. This method of bundling compromised email attachments within other email attachments allows third parties to bypass poorly implement security software or email attachment scanners. Considering this, PC security experts strongly counsel computer users to avoid opening any unsolicited email attachment, even supposing they were sent from known persons. In many cases, close sources may have been infected so that their email address is then used to send out spam email like those used in the TSPY_ZBOT.YYKE attack.

Once the Upatre Trojan variant contained in the corrupted spam email attachment is opened, it infects the victim's computer and begins to download other threats from a remote server. Analyzed variants of this threat would download the TSPY_ZBOT.YYKE. This threatening Trojan has both banking Trojan and spy capabilities and may also install a Necurs Trojan variant. This threat disables security software on the victim's computer in order to make its attacks more devastating and to make the victim's computer more vulnerable to other forms of threats.

It is important to note that Upatre is not only associated with TSPY_ZBOT.YYKE. It has also been linked to threatening ransomware infections that will encrypt the contents of the victim's hard drive. This makes TSPY_ZBOT.YYKE particularly damaging, as TSPY_ZBOT.YYKE can not only endanger your privacy, but also may cause you monetary losses.

Trending

Most Viewed

Loading...