Password-Stealing ‘Dorkbot’ Virus Is On The Prowl In Indian Cyberspace

Cyber security sleuths have alerted Indian internet users against the malicious activity of an online virus called ‘dorkbot’ which perpetrates itself through social networking sites and steals sensitive personal data and passwords of a user.

The malware, a variant of online virus and worm, has been specifically seen affecting operating systems running on Windows in the recent past.

b’Representational image | Source: Reuters’

“It has been observed that the variants of malware named as ‘dorkbot’ targeting windows operating systems, are spreading.

“The malware belongs to the family of worms having backdoor functionality and spreads through various vectors including drive-by-download attacks, social networking sites and compromised websites with browser exploits via removable drives in the form of auto-run exploits or by means of malicious links in instant messaging chats or internet relay chats,” a latest advisory issued by the Computer Emergency Response Team of India (CERT-In) said.

The CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of the Indian internet domain.

The deadly virus, with almost a dozen aliases, is capable of stealing sensitive information from infected machine including stored passwords, browser data, cookies and has a smart and lethal potential to take complete control of the affected system, it said.

b’Representational image | Source: Reuters’

The cyber security agency said the malware can hide itself by over-writing, can collect system information such as OS (operating system) information, user privileges and apps installed on the system and can act to aid remote access of the infected machine to an attacker.

It destructs and infects a system by acquiring fake identities of Facebook, Skype or any other social media platform and lowers its immunity against a potential virus attack.

“To hide itself from detecting by anti-virus solutions, the malware injects its code into files like cmd.exe, ipconfig.exe, regedit.exe, regsvr32.exe, rundll32.exe, verclsid.exe and explorer.exe,” the advisory said.

(Feature image source: Representational image | Reuters)

With inputs from PTI

You might also like
Delhi Air Pollution: Stage IV Curbs to Now Apply at Stage III Under New GRAP Rejig — Full List of Restrictions
Seven Maoists Killed in Andhra Pradesh Encounter a Day After Madvi Hidma’s Elimination
Delhi Air Quality Deteriorates to ‘Severe’; Construction Halted, Schools Shift to Hybrid Mode up to Class 5
Dare. Drop. Win. The Creator Rebellion Rides With Pulsar Underground
Snabbit Bags $30Mn in Third Fundraise This Year, Clocks Over 3 Lakh Jobs in October
₹1.2 Crore Delhi Cloud Seeding Trial Fails to Produce Artificial Rain; AAP Takes ‘Lord Indra’ Dig