Vigilante Malware
Summary
Different cybercriminals have different goals - spying on the unsuspecting users, stealing sensitive data and then uploading it to a remote server, capturing pressed keys to obtain login or payment credentials, hijacking the resources of the infected device and then using them to mine for crypto-coins, or encrypting the users data and demanding a ransom for its restoration. Furthermore, to increase the size of the corrupted archive artificially, it includes non-functional files of random length. Once the threat sneaks itself onto the users device, it obtains the name of the file it was executed and the systems IP address and reports them to the attackers server in the form of an HTTP GET request. In practice, any requests made to this address do not reach the Internet but are instead rerouted back to the system. After all, the Vigilante malware doesn’t have the capability to establish a persistence mechanism on the infected systems.