DropBook Backdoor

General News

Summary

The hackers usually deploy phishing emails that use documents discussing significant events in the selected regions as a lure tricking users into downloading a compromised file. To confirm that it is infecting a suitable target, the DropBook Backdoor performs a check for the presence of the Arabic language on the compromised computer. Although Quasar is a threatening tool, it offers cybercriminals an easy way to establish keylogging, eavesdropping, and data-harvesting routines on the infected system. The MoleRats hackers have incorporated the rising trend among threat actors of using legitimate cloud services and social platforms as part of the Command-and-Control (C2, C&C) structure of their malware creations quickly. At the same time, it exploits Dropbox as a storage for the stolen user data and as a hosting service for the additional espionage payloads.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M