
Dell SonicWALL Threats Research team captured multiple spam campaigns serving newer variant of Tepfer Infostealer Trojan. The malware arrives in an e-mail attachment using themes shown below:
The malware executable inside the zip attachment uses Adobe PDF file icon and also uses official Microsoft Window's application metadata to disguise itself as seen below:
Infection Cycle
The malware executable will perform following activities, if the user is tricked into opening the file:
The downloaded Zeus payload is detected as GAV: Zbot.AAN_65 (Trojan).
Dell SonicWALL Gateway AntiVirus has blocked close to 1 million instances of these spammed Infostealer variants in past one week. Below is the geographic distribution of this Infostealer spam campaign:
Dell SonicWALL Gateway AntiVirus provides protection against this threat with the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News