In the first part of our analysis we looked at the distribution and infection mechanisms used by the Flashfake (a.k.a. Flashback) malicious program, which by the end of April 2012 had infected over 748,000 Mac OS X computers. In this second part well look at its other functions and how the cybercriminals behind Flashfake are cashing in on the botnet they have created. The Flashfake program is made up of multiple modules as well as a dynamic library that is injected into browser processes.”]
Source: https://securelist.com/the-anatomy-of-flashfake-part-2/36565/