Dridex

Dridex
Common nameDridex


TypeTrojan
SubtypeBanking trojan
Author(s)Necurs Maksim Yakubets

Dridex

Dridex also known as Bugat and Cridex is a form of malware that specializes in stealing bank credentials via a system that utilizes macros from Microsoft Word.[5]

The targets of this malware are Windows users who open an email attachment in Word or Excel, causing macros to activate and download Dridex, infecting the computer and opening the victim to banking theft.

The primary objective of this software is to steal banking information[6] from users of infected machines to immediately launch fraudulent transactions. Bank information for the software installs a keyboard listener and performs injection attacks. During 2015, theft caused by this software were estimated at £20 million in the United Kingdom and $10 million in the United States. By 2015, Dridex attacks had been detected in more than 20 countries. In early September 2016, researchers spotted initial support for targeting cryptocurrency wallets.[7]

In December 2019, US authorities filed charges against two suspects believed to have created the Dridex malware, including the group's alleged leader.[8]

Evil Corp

Evil Corp (a.k.a. Dridex and INDRIK SPIDER) is a Russian hacking group that has been active since 2009.[9] In 2019, the Federal Bureau of Investigation (FBI) named nine alleged members of the group, including them of extorting or stealing over $100,000,000 through hacks that affected 40 countries.[10] The United States Department of the Treasury additionally imposed sanctions against the group.[11] In November 2021, the British Broadcasting Company published an investigation which found that the two alleged leaders of the group were living openly in Russia.[10][12]

See also

References

This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.