Newly detected versions of the Lethic botnet are digitally signed using stolen credentials similar to those used by the Stuxnet worm. Web security firm zScaler intercepted new Lethic variants that were signed using legitimate digital signatures belonging to Taiwanese semiconductor firm Realtek Semiconductor Corp. That s one of two firms whose credentials were used to help the StUXnet worm fool detection systems and install itself on target systems. The malware takes aim at Postgres database servers with never-before-seen techniques.
Source: https://threatpost.com/zscaler-resurgent-lethic-using-stuxnet-tricks-111010/74663/

