• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Russian Torrenting Client Caused a Malware Outbreak

March 17, 2018Simeon Georgiev

Nearly 400,000 users were left in utter disarray after it emerged that a massive, chain malware attack had just taken place. The power behind the malware outbreak is believed to be Russian, as the popular torrenting site MediaGet was revealed to be a Russian mirror site working as a magnet link. It is still unclear just how many actual accounts had their sensitive information exposed or stolen due to the attack.

The outbreak is believed to have initiated after March 6 when several users complained about their systems displaying unusual signs of being compromised. Microsoft released a statement on the same day stating that the Windows Defender had picked up and managed to contain a massive malware operation that had sprung a surprise on them. The attack is believed to have targeted mostly users of Russian and Turkish origin. The malware has been codenamed Dofoil (Smoke Leader) Trojan and operates by infecting a computer and then moving on to all other systems on the similar network. Computers that had been plugged in on shared networks are said to have been the biggest victims of this.

A few hours later, Microsoft did release an in-depth report of how the malware had operated and why the attack had probably occurred at all. Windows did accept responsibility for failing to react fast enough, which would have spared a lot of users and their PCs from being infected.

The in-depth report also contains information that this might not have been simply a malware attack as the Dofoil could also potentially try reinstalling itself. Additionally, it could also try installing a Minero miner. This has been a distinctive feature of most malware attacks since the middle of 2017, most of them try installing a cryptominer concurrently on the infected PC. It looks more and more likely that these malware programs are now acting as intrusion bots meant to install the miners on infected PCs.

The exact details of how this malware made its way into the targeted users’ PCs are still something which is unclear. However, it is believed that Mediaget might have generated a file titled my.dat that had attached itself to files that individual users downloaded manually from different torrent sites.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Google Set to Ban Cryptocurrency – Related Ads Next post Chinese botnet army reaches 5 million Android devices mark

Related Articles

Experts Discover a Variant of Cryptomix Ransomware

February 20, 2018Simeon Georgiev

Have a Machine Infected by Ransomware? Here’s What You Should Do

February 28, 2018Simeon Georgiev
Have a Machine Infected by Ransomware?

EITest HoeflerText potential Scam Spreading Netsupport Manager and GandCrab

March 1, 2018Simeon Georgiev
EITest HoeflerText potential Scam Spreading Netsupport Manager and GandCrab

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.