
SonicWALL UTM Research team observed reports of Bamital Trojan Installer being distributed in the wild as part of Pay-Per-Install campaign by the malware authors.
Bamital Trojan family is known to monitor user browsing activity, modify internet search results and display advertisements generating revenue for the malware authors. SonicWALL is seeing an increase in the number of Bamital infected executable files starting early August.
A forum posting was seen on pay-per-install.org yesterday that advertised revenue sharing per installations i.e. infections of Bamital Trojan (The post has been removed now). As seen in the image below, they assign a numeric ID to the users signing up and provide a binary based on that user ID which can be used to track the number of installations. Malware authors are offering up to 800$ per 1000 infections which gives an indication of the amount of money they are making out of it.
The domain advertised in the post is of Russian origin and is actively serving Bamital Trojan Installer at the time of writing this alert. The malicious installer executable performs following activities upon execution:
SonicWALL Gateway AntiVirus provides protection against this Trojan via following signatures:
Share This Article

An Article By
An Article By
Security News
Security News