The Terdot Trojan is both spread by email, using infected attachments, and by the Sundown exploit kit. Its main targets are in the US, Canada, the UK, Germany, and Australia. It uses a complex method to download and activate the malware on the targeted system. Once established, it uses its own security certificate to bypass TLS restrictions and set up a man-in-the-middle (MitM) proxy. The malware can also steal account login information and cookies so operators can hijack the social network account and re-sell access to it.”]

