Ramdo Click-Fraud Malware Continues to Evolve

  • 12 April 2016
  • 1 reply
  • 105 views

Userlevel 7
Badge +54
By Eduard Kovacs on April 12, 2016
 
Researchers at Dell SecureWorks and Palo Alto Networks have teamed up to analyze the Ramdo click-fraud malware, a threat that has been infecting computers around the world since late 2013.

Ramdo, also known as Redyms, helps cybercriminals make a profit by silently clicking on online ads from infected systems. The malware is also capable of downloading and installing additional malicious software on infected devices.

Once it infects a computer — primarily by leveraging exploit kits such as Angler, RIG and Magnitude — Ramdo checks for the presence of sandboxes and virtual machines, which could indicate that the threat is being analyzed by researchers. If these types of applications are not detected, the malware creates a new Windows process and injects a malicious DLL into it.
 
Full Article

1 reply

Userlevel 7
OooooH, had not heard of this one before...sounds nasty...especially the 'silent' bit. :(

Reply