Trojan-Dropper:W32/CosmicDuke steals information from an infected system using keylogging, screen captures and stealing file and clipboard data. Harvested data is forwarded to a remote server via FTP.
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
The CosmicDuke trojan-dropper appears to be spread in 'bait' image, document and PDF files, which contain an exploit or a buried Windows executable program. Once the bait file is opened, the exploit or program is launched and begins to harvest data from the infected machine.
In addition to its information-stealing activities, CosmicDuke is notable for sharing code with MiniDuke, a malware known to have been used to attack various NATO and European government agencies in February 2013.
For more information, see Labs Weblog post:CosmicDuke: Cosmu With a Twist of MiniDuke or download the whitepaper.
Date Created: -
Date Last Modified: -