Overdue Invoices Hide Pony Info-Stealing Trojan

  • 28 October 2014
  • 0 replies
  • 161 views

Userlevel 7
Badge +54
Cybercriminals use the double-extension trick
By Ionut Ilascu on October 28th, 2014 A new email campaign has been detected to deliver Pony stealer disguised as a PDF file purporting to contain details about an overdue invoice.
The document has a double extension and is, in fact, a COM executable file that includes commands for downloading the malware from a compromised website, after running a few unpackaging procedures.

The newest variants of Pony feature capabilities for stealing crypto-currency wallets available on the infected computers but can also exfiltrate sensitive information as well as download other malware families. Full Article

0 replies

Be the first to reply!

Reply