<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>trojan Archives - Linux Windows and android Tutorials</title>
	<atom:link href="https://www.osradar.com/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osradar.com</link>
	<description>tutorials and news and Seurity</description>
	<lastBuildDate>Tue, 31 May 2022 03:55:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.8.12</generator>
	<item>
		<title>What does a Trojan do on your computer and how to avoid it?</title>
		<link>https://www.osradar.com/what-does-a-trojan-do-on-your-computer-and-how-to-avoid-it/</link>
					<comments>https://www.osradar.com/what-does-a-trojan-do-on-your-computer-and-how-to-avoid-it/#respond</comments>
		
		<dc:creator><![CDATA[roger]]></dc:creator>
		<pubDate>Thu, 02 Jun 2022 21:54:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=36012</guid>

					<description><![CDATA[<p>There are many types of computer attacks that can compromise security when surfing the Internet. It also happens when using any device. Today we are going to talk about one of them. We are going to explain what a Trojan is and what it does. In addition, we will give you tips on how to [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/what-does-a-trojan-do-on-your-computer-and-how-to-avoid-it/">What does a Trojan do on your computer and how to avoid it?</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>There are many types of computer attacks that can compromise security when surfing the Internet. It also happens when using any device. Today we are going to talk about one of them. We are going to explain what a Trojan is and what it does. In addition, we will give you tips on how to avoid this type of malware. In fact, we will give you indications so that security is always present and you don&#8217;t have any problem.</p>



<h2>What is a Trojan</h2>



<p>Foremost, let&#8217;s explain what exactly a Trojan consists of. Indeed, its name comes from the Trojan horse, since in this case, it is a malicious software that disguises itself as a legitimate file. It can be a text document, an image, or a program. In short, anything that pretends to be something secure, but in reality it is a security problem. Certainly, the principle of a Trojan is the same. That is, hiding malware inside a file that looks legitimate. However, not all of them have the same objective. Normally, an attacker will seek to take control of a computer in some way. In this way, he will be able to steal data or even sneak in other threats.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="823" src="https://www.osradar.com/wp-content/uploads/2022/05/tro-1024x823.png" alt="" class="wp-image-36013" srcset="https://www.osradar.com/wp-content/uploads/2022/05/tro-1024x823.png 1024w, https://www.osradar.com/wp-content/uploads/2022/05/tro-300x241.png 300w, https://www.osradar.com/wp-content/uploads/2022/05/tro-768x617.png 768w, https://www.osradar.com/wp-content/uploads/2022/05/tro-696x560.png 696w, https://www.osradar.com/wp-content/uploads/2022/05/tro-1068x859.png 1068w, https://www.osradar.com/wp-content/uploads/2022/05/tro.png 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>A Trojan can affect both computers and mobile devices. In addition, there are Trojans for different operating systems. It is a type of malware that has adapted over time. Therefore, cybercriminals meet their objectives in terms of stealing information or taking control of systems.</p>



<p>Examples of major Trojans are Zeus, Emotet, Petya or WannaCry. They have put numerous companies and also private users at risk. On the other hand, these types of attacks do not only affect home users, but also target important organizations.</p>



<h2>What is its function and how does it affect</h2>



<p>Trojans can have different functions and characteristics. In fact, not all act the same and not all are equally dangerous. Trojans can have different functions and characteristics. In fact, not all of them act the same and not all of them are equally dangerous. Let us explain what their main functions are. In addition, how it will affect the security of both home users and companies and organizations that are infected.</p>



<h3>Create a back door</h3>



<p>The first goal of a Trojan is to create a backdoor. This is one of the most common attacks that can occur. This door allows the attacker to gain some control or access to the device. For example, he will be able to sneak data, malicious files that obtain information, etc.</p>



<figure class="wp-block-image size-full"><img loading="lazy" width="623" height="542" src="https://www.osradar.com/wp-content/uploads/2022/05/tro2.png" alt="" class="wp-image-36014" srcset="https://www.osradar.com/wp-content/uploads/2022/05/tro2.png 623w, https://www.osradar.com/wp-content/uploads/2022/05/tro2-300x261.png 300w" sizes="(max-width: 623px) 100vw, 623px" /></figure>



<p>Usually, the victim does not quickly become aware of the problem. That is, there are no noticeable symptoms such as a malfunction at first. As a result, an attacker can have access to a system for a long time until he is discovered, so he has room to collect data.</p>



<h3>Hidden downloads</h3>



<p>There are also download Trojans. They aim to download content onto the computer without the victim&#8217;s permission. This will be done in a hidden way, through commands that have been previously programmed to carry out certain actions.</p>



<p>Usually, these hidden downloads are bundled with more malicious software. In addition, they can download viruses and other varieties of malware that affect security and privacy. For example, they could download a keylogger that steals the passwords that the victim puts on the computer.</p>



<h3>Stealing information</h3>



<p>Another clear function is to steal information from the infected computer. They can collect personal data from the victim, spy, collect browsing-related data. Moreover, programs used, files on the computer, etc. In short, they can steal all kinds of data.</p>



<figure class="wp-block-image size-full"><img loading="lazy" width="844" height="422" src="https://www.osradar.com/wp-content/uploads/2022/05/tro3.png" alt="" class="wp-image-36015" srcset="https://www.osradar.com/wp-content/uploads/2022/05/tro3.png 844w, https://www.osradar.com/wp-content/uploads/2022/05/tro3-300x150.png 300w, https://www.osradar.com/wp-content/uploads/2022/05/tro3-768x384.png 768w, https://www.osradar.com/wp-content/uploads/2022/05/tro3-696x348.png 696w" sizes="(max-width: 844px) 100vw, 844px" /></figure>



<p>This data can be used for different purposes. For example, they could be used to carry out personalized phishing attacks, to steal confidential data from a company or an organization. They can then sell it to competitors or even extort the data and threaten to make it public.</p>



<h3>DDoS attacks</h3>



<p>On the other hand, mention must also be made of DDoS or distributed denial of service attacks. A Trojan can launch such attacks to saturate a server. This way it can respond to legitimate requests that another user will make and find that it does not work.</p>



<figure class="wp-block-image size-full"><img loading="lazy" width="700" height="500" src="https://www.osradar.com/wp-content/uploads/2022/05/tro4.png" alt="" class="wp-image-36016" srcset="https://www.osradar.com/wp-content/uploads/2022/05/tro4.png 700w, https://www.osradar.com/wp-content/uploads/2022/05/tro4-300x214.png 300w, https://www.osradar.com/wp-content/uploads/2022/05/tro4-696x497.png 696w" sizes="(max-width: 700px) 100vw, 700px" /></figure>



<p>Trojans can be designed for this purpose, and the objective here is to affect the smooth running of a company, for example. They can serve as a way to launch attacks that compromise computers because of launching multiple requests.</p>



<h2>Tips to avoid this type of malware</h2>



<p>As you have seen, a Trojan is a major security threat. It is essential to take measures to avoid falling victim to these attacks. Therefore, we are going to give some essential tips to ensure that our devices are properly protected and that no problems arise.</p>



<h3>Use security software</h3>



<p>Something significant to maintain security and avoid Trojans and other threats is to have a good <a href="https://www.osradar.com/the-best-free-antivirus-for-windows-in-2021/" target="_blank" rel="noreferrer noopener">antivirus.</a> There are many options. One of the most used is Windows Defender itself, the antivirus that comes with Microsoft systems. However, there are many free and paid options. For example, Avast or Bitdefender are some alternatives.</p>



<h3>Keeping everything up to date</h3>



<p>Of course, it is essential to keep everything <a href="https://support.microsoft.com/en-us/windows/windows-update-faq-8a903416-6f45-0718-f5c7-375e92dddeb2" target="_blank" rel="noreferrer noopener">up to date.</a> In fact, cybercriminals can take advantage of a vulnerability to sneak in a Trojan. They could use a bug on Windows or in a program you use to sneak in malicious software without you noticing it and be able to control the device.</p>



<h3>Install only official applications</h3>



<p>Something very important, and not always taken into account, is to install only official applications. It is true that there are many options for almost everything, but the ideal is to use only programs that are reliable, secure and that have not been maliciously modified to steal data or, in this case, to install Trojans. To achieve this it is important to download programs only from official sources. For example go to the official website of the application or use secure stores such as Google Play.</p>



<h3>Common sense</h3>



<p>But undoubtedly the most important thing is common sense. In most cyber attacks the hacker will need us to make a mistake. For example, clicking on a dangerous link, downloading an insecure file, etc. This makes it essential to take care when browsing and not to make mistakes.</p>



<p>For example, you should make sure not to download attachments that come to you by email if you do not really know the source and do not know for sure whether or not it may be a threat. The same when logging in or opening any link. You should always check that it is reliable and is not going to be a problem.</p>



<p></p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/what-does-a-trojan-do-on-your-computer-and-how-to-avoid-it/">What does a Trojan do on your computer and how to avoid it?</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/what-does-a-trojan-do-on-your-computer-and-how-to-avoid-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Learn about the Ramnit threat and how to remove it from Windows 10.</title>
		<link>https://www.osradar.com/learn-about-the-ramnit-threat-and-how-to-remove-it-from-windows-10/</link>
					<comments>https://www.osradar.com/learn-about-the-ramnit-threat-and-how-to-remove-it-from-windows-10/#respond</comments>
		
		<dc:creator><![CDATA[roger]]></dc:creator>
		<pubDate>Sat, 24 Oct 2020 21:30:33 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[ramni]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[windows Security]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=24746</guid>

					<description><![CDATA[<p>Hello! There are computer security threats that can appear spontaneously. But, then they may not last long. On the other hand, malware can adapt to security measures and improve over time. Today we will talk about Ramnit, a new threat for Windows users and how to remove it. Ramnit, the Windows threat that must be [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/learn-about-the-ramnit-threat-and-how-to-remove-it-from-windows-10/">Learn about the Ramnit threat and how to remove it from Windows 10.</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Hello! There are computer security threats that can appear spontaneously. But, then they may not last long. On the other hand, malware can adapt to security measures and improve over time. Today we will talk about Ramnit, a new threat for Windows users and how to remove it.</p>



<h2>Ramnit, the Windows threat that must be eliminated as soon as possible.</h2>



<p>In this case, the threat is not recent as Ramnit has been attacking Windows for years. Furthermore, it is very dangerous because if it is not eliminated it can spread quickly. It is also possible that it will damage other devices. However, when it comes to protecting the system from threats, speed is key. Since it is very important to make an early detection of the attacker. Consequently, it is possible to stop the mechanism of action in time. For example, <a href="https://www.osradar.com/a-new-type-of-ransomware-seriously-threatens-windows-10/" target="_blank" rel="noreferrer noopener">ransomware</a> attacks can take weeks to complete. In the case of Ramnit, detection time is vital. Since the Trojan has the possibility to spread quickly through the computer files.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="781" src="//1081754738.rsc.cdn77.org/wp-content/uploads/2020/10/germ-158107_1280-1024x781.png" alt="" class="wp-image-24747" srcset="https://www.osradar.com/wp-content/uploads/2020/10/germ-158107_1280-1024x781.png 1024w, https://www.osradar.com/wp-content/uploads/2020/10/germ-158107_1280-300x229.png 300w, https://www.osradar.com/wp-content/uploads/2020/10/germ-158107_1280-768x586.png 768w, https://www.osradar.com/wp-content/uploads/2020/10/germ-158107_1280-696x531.png 696w, https://www.osradar.com/wp-content/uploads/2020/10/germ-158107_1280-1068x814.png 1068w, https://www.osradar.com/wp-content/uploads/2020/10/germ-158107_1280.png 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2>How Ramnit spreads</h2>



<p>This threat is usually spread through infected USB sticks. In effect, the malware is copied with a random file name. Of course, before that the threat must come from some other source. In other words, first a computer is infected with malware. Then the connected USB memory is contaminated and then spreads to another computer. Generally, this threat usually comes with the download of maliciously modified software. The most common sources are websites that offer pirated software and crackers.</p>



<p>Ramnit has the ability to infect EXE and HTML files. Then, when you get to the equipment you are able to open a back door. This is used by an attacker remotely to download new threats and execute malicious files. Consequently, that is the time to eliminate the threat. That is, just before allowing an attacker to access the system. Otherwise, it could spread to all the files on the computer and make it unusable.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="887" height="1024" src="//1081754738.rsc.cdn77.org/wp-content/uploads/2020/10/html-154434_1280-887x1024.png" alt="" class="wp-image-24749" srcset="https://www.osradar.com/wp-content/uploads/2020/10/html-154434_1280-887x1024.png 887w, https://www.osradar.com/wp-content/uploads/2020/10/html-154434_1280-260x300.png 260w, https://www.osradar.com/wp-content/uploads/2020/10/html-154434_1280-768x886.png 768w, https://www.osradar.com/wp-content/uploads/2020/10/html-154434_1280-696x803.png 696w, https://www.osradar.com/wp-content/uploads/2020/10/html-154434_1280-1068x1233.png 1068w, https://www.osradar.com/wp-content/uploads/2020/10/html-154434_1280.png 1109w" sizes="(max-width: 887px) 100vw, 887px" /></figure>



<h2>How to remove Ramnit from your computer</h2>



<p>Once the malware infects the computer, it is a race against time. Indeed, the user must act quickly before the system is seriously affected and the threat spreads. Fortunately, there are timely actions to remove this dangerous threat.</p>



<h4>Perform a full scan with Windows Defender</h4>



<p>To the surprise of many, Windows Defender has scored very well on effectiveness measures. Please remember that this is Microsoft&#8217;s bet against security threats. Additionally, it comes included and perfectly integrated with the system. Well, sometimes all it takes is a complete and exhaustive examination of the system to put an end to Ramnit. Also, pay special attention to HTML and .exe files. Inasmuch as,  these are the input elements of the threat. On the other hand, it is imperative to perform an examination of any USB memory connected to the computer. In this way, the chains of contagion are cut.</p>



<h4>Using Symantec Ramnit Removal Tool</h4>



<p>A more specific alternative is to use an Ramnit Removal Tool offered by Symantec. It is specially designed to eliminate this variety of Windows malware. To use it, download it from this <a href="https://www.softpedia.com/get/Antivirus/Removal-Tools/Symantec-Ramnit-Removal-Tool.shtml" target="_blank" rel="noreferrer noopener">link.</a> Next, you just have to run it as it is a portable file. It will automatically start searching for Ramnit on the system and clean it up. In addition, its action mechanism involves closing all processes related to it. Consequently, it acts in a more specific way than any antivirus.</p>



<h2>How to avoid being a victim of Ramnit</h2>



<p>In this post we have seen how this threat acts. But the most important point is to avoid getting infected. In the first place, the most important thing is common sense. That is, only download software from its official sources. In addition, it is never advisable to open suspicious links sent by email. On the other hand, it is very important to keep the system updated. Because updates protect your computer against threats. Finally, a good antivirus is a method of defense against security risks. All right, that&#8217;s it for now. Ultimately we have see, the  Ramnit threat and how to remove it from Windows 10. Please stay tuned for the latest security alerts in Windows 10.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/learn-about-the-ramnit-threat-and-how-to-remove-it-from-windows-10/">Learn about the Ramnit threat and how to remove it from Windows 10.</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/learn-about-the-ramnit-threat-and-how-to-remove-it-from-windows-10/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Android Trojan Steals Info from Messenger, Skype, Twitter &#038; More</title>
		<link>https://www.osradar.com/android-trojan-steals-info-from-messenger-skype-twitter-more/</link>
					<comments>https://www.osradar.com/android-trojan-steals-info-from-messenger-skype-twitter-more/#respond</comments>
		
		<dc:creator><![CDATA[Mel]]></dc:creator>
		<pubDate>Thu, 05 Apr 2018 04:38:59 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[android malware]]></category>
		<category><![CDATA[android trojan]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=2403</guid>

					<description><![CDATA[<p>Android is the most popular operating system for smart devices. As Android is open-source, powerful yet flexible, smartphone manufacturers always choose it as their devices’ OS. Due to the immense popularity, hackers also target Android system for hacking. Recently, a new Android Trojan was identified that extracts information from other apps like Messenger, Twitter, Skype, [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/android-trojan-steals-info-from-messenger-skype-twitter-more/">Android Trojan Steals Info from Messenger, Skype, Twitter &amp; More</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Android is the most popular operating system for smart devices. As Android is open-source, powerful yet flexible, smartphone manufacturers always choose it as their devices’ OS. Due to the immense popularity, hackers also target Android system for hacking. Recently, a new Android Trojan was identified that extracts information from other apps like Messenger, Twitter, Skype, WeChat, Viber, Line etc.</p>
<p>According to security researchers from Trustlook, the Trojan is quite simple in design but uses an advanced method to hide from the system and other defenses.</p>
<h3>How the Android Trojan works</h3>
<p>The Trojan gains access to boot persistence and executes itself at every boot. At first, the malware unpacks the malicious code from the app’s resources. Then, it tries to modify a bash file at “/system/etc/install-recovery.sh”. If the modification is successful, it allows the malware to run at every boot.</p>
<p>Then, its task is to extract the data from the IM clients. The most popular ones are already mentioned above. The complete list of vulnerable IM clients can be found <a href="https://blog.trustlook.com/2018/04/02/a-trojan-with-hidden-malicious-code-steals-users-messenger-app-information/">here</a>. After collecting the information, the malware sends the data to a remote server. The server’s IP address is loaded from a pre-configured file.</p>
<p>This malware was identified inside a Chinese app named “Cloud Module” (in Chinese). The package was named “com.android.boxa”.</p>
<h3>Evasion techniques</h3>
<p>According to the researchers of Trustlook, despite simple workflow of the Android Trojan (running persistently, extracting info and uploading to remote server), it’s quite efficient in hiding itself. For example, it implements anti-emulator &amp; debugger detection that allows avoiding dynamic analysis. Moreover, it hides strings inside its source code for protection against thwart lackadaisical code reversing.</p>
<p>The method of workflow tells that the attacker is collecting personal information (chat, images or videos) for using later in extortion attempts or blackmailing from the high-profile victims. Researchers didn’t share any information how the malware spreads itself. However, as there’s no Play Store in China, the culprits are most likely spreading the malware via 3<sup>rd</sup>-party app stores and Android app forums.</p>
<p>There are also other attempts from Chinese vendors that shipped Android smartphones with built-in Trojan! <a href="https://www.osradar.com/pre-installed-malware-in-android/">Learn more about the pre-installed Trojan on the Android smartphones</a>.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/android-trojan-steals-info-from-messenger-skype-twitter-more/">Android Trojan Steals Info from Messenger, Skype, Twitter &amp; More</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/android-trojan-steals-info-from-messenger-skype-twitter-more/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>TrickBot Trojan is Upgrading</title>
		<link>https://www.osradar.com/trickbot-trojan-is-upgrading/</link>
					<comments>https://www.osradar.com/trickbot-trojan-is-upgrading/#respond</comments>
		
		<dc:creator><![CDATA[Mel]]></dc:creator>
		<pubDate>Fri, 23 Mar 2018 14:45:03 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=2257</guid>

					<description><![CDATA[<p>Banking is one of the most sensitive areas of security. It’s directly related to money transfer and requires the best protection available. TrickBot is an infamous banking Trojan. Recently, security researchers identified that the latest edition now contains a screen locker component. Although the finding suggests that it’s still under development, it poses an immense [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/trickbot-trojan-is-upgrading/">TrickBot Trojan is Upgrading</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Banking is one of the most sensitive areas of security. It’s directly related to money transfer and requires the best protection available. TrickBot is an infamous banking Trojan. Recently, security researchers identified that the latest edition now contains a screen locker component. Although the finding suggests that it’s still under development, it poses an immense threat to the world of security.</p>
<p>TrickBot itself is an old banking Trojan that infected several banks in the UK, US, and Australia. In recent days, the malware is being revitalized with improved capabilities. That’s what researchers found – a screen locker. It strongly suggests that the malware will now start locking devices for ransom if the device user doesn’t appear to be e-banking user.</p>
<h3>The new component</h3>
<p>The screen locker module is a part of all the programs that TrickBot setup in the infected system. At first, it was just a banking Trojan. In the past days, it has improved a lot and transformed into a tool for dropping malware into systems.</p>
<p>The latest version was first sighted on March 15 this year. TrickBot authors infect a victim by initializing a malware strain that specializes in downloading other modules that perform all the different actions. Before the date, TrickBot consisted of a few modules – a banking Trojan, a spam email sending module and an SMB self-replicating worm to spread throughout a network.</p>
<p>At the date, TrickBot started downloading a new file – tabDll32.dll (tabDll64.dll in some cases). This new file loaded additional 3 files.</p>
<ul>
<li>Spreader_x86.dll – Module that helps the Trojan spread throughout the connected network. It works via SMB by exploiting EternalRomance and other exploits that were patched by the MS17-010 security patch.</li>
<li>SsExecutor_x86.exe – Runs alongside the first module. It also establishes boot persistence on the infected system.</li>
<li>ScrenLocker_x86.dll – A module that locks the screen. However, doesn’t encrypt files in the system (ransomware). Currently inactive.</li>
</ul>
<p>Here is the tweet from MalwareTechLab that found the new TrickBot modules.</p>
<h3>The new module is for enterprise networks</h3>
<p>All the new 3 files work together in the system, irrespective of the original worm component. After spreading throughout the entire network, the screen locker module is triggered to lock all the computer’s screens.</p>
<p>This workflow leads researchers to think that the new system is being developed for enterprise networks where hundreds of machines are connected with each other. Although there’s no file encryption module/action observed, there’s a strong chance that this Trojan will become the next ransomware of the century.</p>
<h3>How to stay protected</h3>
<p>According to the workflow of the improved Trojan, it uses several system exploits that are already fixed with the latest system patches. Moreover, as long as it’s discovered by security researchers, you can expect that security vendors are already at work to defend against it.</p>
<p>So, the first thing to do is to update your system to the latest available patches. These files are from Windows system. If you don’t want to waste your time waiting for the lengthy update process, you can <a href="https://www.osradar.com/how-to-update-windows-offline/">update your Windows offline</a>. You also need a good antivirus program to defend against the malware. You can check out the <a href="https://www.osradar.com/best-antivirus-software-2018/">best antivirus software of 2018</a>.</p>
<p>Above all, follow cautions with your usage habit so that no other malware along with TrickBot gets into your system.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/trickbot-trojan-is-upgrading/">TrickBot Trojan is Upgrading</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/trickbot-trojan-is-upgrading/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Pre-installed Trojan in Android Smartphones</title>
		<link>https://www.osradar.com/pre-installed-malware-in-android/</link>
					<comments>https://www.osradar.com/pre-installed-malware-in-android/#respond</comments>
		
		<dc:creator><![CDATA[Mel]]></dc:creator>
		<pubDate>Tue, 06 Mar 2018 08:26:35 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[android trojan]]></category>
		<category><![CDATA[dr. web]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=2087</guid>

					<description><![CDATA[<p>Recently, Android security provider company Dr. Web reported that a good number of the Android phone in the market come up with a pre-installed Trojan named “Android.Triada.231”. This Trojan is capable of stealing any information it needs. The company discovered the Trojan in mid-2017 and after an in-depth research, they found out that over 40 [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/pre-installed-malware-in-android/">Pre-installed Trojan in Android Smartphones</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Recently, Android security provider company Dr. Web reported that a good number of the Android phone in the market come up with a pre-installed Trojan named “Android.Triada.231”. This Trojan is capable of stealing any information it needs.</p>
<p>The company discovered the Trojan in mid-2017 and after an in-depth research, they found out that over 40 smartphone models are affected by it. These phones are from the low-end category including devices from Umi, Cubot, Doogee &amp; Leagoo etc.</p>
<p>Dr. Web reported the issue to the companies and in one particular case, it was discovered that the culprit behind the Trojan was a partnership with a software developing company in Shanghai. The contract required the OEMs to pre-install one of their software in the operating system.</p>
<h3>How “Android.Triada.231” works</h3>
<p>This malware is extremely dangerous as it runs since the starting of the phone where there’re a few setup processes. This could lead to serious situations.</p>
<p>According to Dr. Web, the Trojan infect an important Android process named “Zygote”. This process launches all the apps in Android. Thus, once the Trojan is inside the module, it can get inside each and every application that runs on the system.</p>
<p>Thus, the Trojan obtains the ability to carry out any malicious activity without the user’s notice. It also cleverly downloads and launches additional software. The file “libandroid_runtime.so” is the home of “Android.Triada.231”, an important system library for the Android operating system. The main feature is, this Trojan isn’t distributed as an additional software and infects the system during manufacturing. The users who purchase the phone gets built-in Trojan in the way.</p>
<p>The number of possible infected devices can go even higher. However, the 40 designs are confirmed that those are compromised by the Trojan. There could be other phones having the same issue as well.</p>
<h3>How to stay secured</h3>
<p>This is not an easy process to remove the Trojan. The malware comes built-in; in other words, as system software. General antivirus and security apps can’t remove the Trojan even if that’s identified. Giving a system reset doesn’t work, as the system’s backup image is the source of the Trojan.</p>
<p>The best way to stay secure from this malware is to change the smartphone. If you’re an advanced user, you can try rooting the device and fix the problem with antivirus or install a custom ROM. The latest Galaxy S9 is also announced. <a href="https://www.osradar.com/galaxy-s9-announced-everything-know/">Learn more about Galaxy S9</a>.</p>
<p>Here’s the complete list of all the infected (confirmed) devices. Take quick actions if you own any of these.</p>
<ul>
<li>Leagoo M5</li>
<li>Leagoo M5 Plus</li>
<li>Leagoo M5 Edge</li>
<li>Leagoo M8</li>
<li>Leagoo M8 Pro</li>
<li>Leagoo Z5C</li>
<li>Leagoo T1 Plus</li>
<li>Leagoo Z3C</li>
<li>Leagoo Z1C</li>
<li>Leagoo M9</li>
<li>ARK Benefit M8</li>
<li>Zopo Speed 7 Plus</li>
<li>UHANS A101</li>
<li>Doogee X5 Max</li>
<li>Doogee X5 Max Pro</li>
<li>Doogee Shoot 1</li>
<li>Doogee Shoot 2</li>
<li>Tecno W2</li>
<li>Homtom HT16</li>
<li>Umi London</li>
<li>Kiano Elegance 5.1</li>
<li>iLife Fivo Lite</li>
<li>Mito A39</li>
<li>Vertex Impress InTouch 4G</li>
<li>Vertex Impress Genius</li>
<li>myPhone Hammer Energy</li>
<li>Advan S5E NXT</li>
<li>Advan S4Z</li>
<li>Advan i5E</li>
<li>STF AERIAL PLUS</li>
<li>STF JOY PRO</li>
<li>Tesla SP6.2</li>
<li>Cubot Rainbow</li>
<li>EXTREME 7</li>
<li>Haier T51</li>
<li>Cherry Mobile Flare S5</li>
<li>Cherry Mobile Flare J2S</li>
<li>Cherry Mobile Flare P1</li>
<li>NOA H6</li>
<li>Pelitt T1 PLUS</li>
<li>Prestigio Grace M5 LTE</li>
<li>BQ 5510</li>
</ul>
<p><span class="td_text_highlight_marker_blue td_text_highlight_marker">source: <a href="http://news.softpedia.com/news/android-phones-caught-selling-with-pre-installed-factory-malware-520058.shtml">Softpedia</a></span></p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/pre-installed-malware-in-android/">Pre-installed Trojan in Android Smartphones</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/pre-installed-malware-in-android/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LuminosityLink &#8211; The Nasty Trojan Taken Out</title>
		<link>https://www.osradar.com/luminositylink-spyware-nasty-spying-tool-taken/</link>
					<comments>https://www.osradar.com/luminositylink-spyware-nasty-spying-tool-taken/#respond</comments>
		
		<dc:creator><![CDATA[Mel K]]></dc:creator>
		<pubDate>Tue, 06 Feb 2018 07:34:08 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[RAT]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=1746</guid>

					<description><![CDATA[<p>LuminosityLink, since 2015, was sold as a remote access tool for Windows system admins and business owners. This is nothing but a Trojan toolkit, a member of the malware family RAT (Remote Access Trojan). According to the UK’s National Crime Agency, they disabled this widely used RAT (remote-access Trojan) tool. This tool was sold in [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/luminositylink-spyware-nasty-spying-tool-taken/">LuminosityLink &#8211; The Nasty Trojan Taken Out</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>LuminosityLink, since 2015, was sold as a remote access tool for Windows system admins and business owners. This is nothing but a Trojan toolkit, a member of the malware family RAT (Remote Access Trojan). According to the UK’s National Crime Agency, they disabled this widely used RAT (remote-access Trojan) tool. This tool was sold in 78 countries and sold to 8,600+ buyers, according to NCA.</p>
<h3>What is LuminosityLink?</h3>
<p>It’s a remote access Trojan toolkit. Using this tool, one can remotely control the clients via Remote Desktop and Remote Webcam. This tool is also able to automatically log keystrokes, recover passwords, search &amp; manage files. It was capable of disabling anti-malware and antivirus programs as well.</p>
<p>This program was available for buyers to buy from <a href="https://web.archive.org/web/20161110132249/https:/luminosity.link/">luminosity.link</a> just for $40. This Trojan was discovered in 2015 and the in-depth report of its full capabilities was published in July 2016. Although it’s not available for buyers anymore, those who purchased previously are still able to infect other victims.</p>
<p>The RAT tool is extremely powerful with a handy control panel, making it very useful for illegal activities including taking screenshots of other systems, search and steal files and even upload other malware without any notice. This is the screenshot of the LuminosityLink Control Panel GUI.</p>
<p><img loading="lazy" class="size-full wp-image-1747 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/02/LuminosityLink-GUI-tool.png" alt="" width="973" height="517" srcset="https://www.osradar.com/wp-content/uploads/2018/02/LuminosityLink-GUI-tool.png 973w, https://www.osradar.com/wp-content/uploads/2018/02/LuminosityLink-GUI-tool-300x159.png 300w, https://www.osradar.com/wp-content/uploads/2018/02/LuminosityLink-GUI-tool-768x408.png 768w, https://www.osradar.com/wp-content/uploads/2018/02/LuminosityLink-GUI-tool-696x370.png 696w, https://www.osradar.com/wp-content/uploads/2018/02/LuminosityLink-GUI-tool-790x420.png 790w" sizes="(max-width: 973px) 100vw, 973px" /></p>
<p>A serious concern is the source code of RAT was never leaked online. It’s one of the best spyware product sold in the past years. A HackForum user is currently providing a free clone of LuminosityLink RAT. Researchers at Proofpoint discovered that hackers used Sundown exploit kit to distribute LuminosityLink. This kit attacked the flaws of Flash Player and older Windows flaws.</p>
<p>By June 2016, Palo Alto Networks identified more than 50,000 attempts of injecting LuminosityLink into their system. Phishing emails containing infected links attempted to distribute this malware as well. The attempts in Palo Alto Networks included 18,000 unique malware sample.</p>
<h3>How to stay secured</h3>
<p>This is a Trojan tool that can affect anyone. If your system’s security isn’t well enough or your activity isn’t careful, it will get into your system without your knowledge.</p>
<p>The procedure staying safe from this Trojan is just the same as other malware. Get a good antivirus or anti-malware to protect your system and keep it up-to-date. You can get a nice idea of a good anti-malware tool from AV-Test. Check out our top 10 antiviruses of 2018.</p>
<p>Don’t open any suspicious file attachments. Don’t download a program from an untrusted source. If you’re a system admin, it’s always a good idea for disabling the unused ports, unused services etc. You can also monitor the outgoing traffic for any suspicious activity.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/luminositylink-spyware-nasty-spying-tool-taken/">LuminosityLink &#8211; The Nasty Trojan Taken Out</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/luminositylink-spyware-nasty-spying-tool-taken/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
