Malware hijacks Microsoft Outlook to send emails with more malware

Researchers have discovered a Trojan that uses Microsoft Outlook to send emails with malware. The Trojan is a variant of the Dyre banking Trojan, also known as Dyreza. The malware has been specifically developed to steal money from online bank accounts.

myce-dyre-infection-chain

The now discovered variant uses email attachments to spread itself. The email attachments resemble fax messages or a message of an undeliverable parcel and contain the Upatre downloader. This downloader installs the Dyre Trojan on the system which in its turn installs a worm on the computer. The worm uses Microsoft Outlook to send out infected emails with the Upatre downloader and the cycle then repeats itself.

The malware doesn't use the address book of its victim, contrary  to what most worms did in the past. After the messages have been sent, the worm removes itself, according to antivirus company Trend Micro.

No posts to display