Blog | G5 Cyber Security

Unholy trinity of AKBuilder, LokiBot and Betabot used in new malware campaigns

In recent weeks, SophosLabs has published papers outlining threats from AKBuilder and Betabot. Now, it appears the bad guys are combining the two in new attack campaigns. The documents initially drop a file that contains two payloads: one, the popular LokiBot credential stealer; the other, something that appears to be a version of BetabOT. The malware is delivered in email messages like this: “Gbor Szappanos said the lab has received and analyzed a handful of AKBuilder-generated documents in the past week.”]

Source: https://nakedsecurity.sophos.com/2017/03/01/unholy-trinity-of-akbuilder-dyzap-and-betabot-used-in-new-malware-campaigns/

Exit mobile version