A new backdoor is targeting users of torrent services.

International antivirus company ESET warns about a new malware that threatens users of torrent sites.

A new backdoor is targeting users of torrent services.

The malware is named GoBot2/GoBotKR. It spreads disguised as various games and applications, as well as pirated copies of movies and TV series. After downloading such content, the user receives files that seem harmless at first glance. However, they actually conceal the malware.

The activation of the malware occurs after clicking on an LNK file. Once GoBotKR is installed, it begins collecting system information: details about the network configuration, operating system, processor, and installed antivirus programs. This information is then sent to a command server, located in South Korea.

The collected data can then be used by cybercriminals to plan various attacks in cyberspace. These may include distributed denial-of-service (DDoS) attacks.


A new backdoor is targeting users of torrent services.

The malware is capable of executing a wide range of commands. Among them: sharing torrents via BitTorrent and uTorrent, changing the desktop background, copying the backdoor to cloud storage folders (Dropbox, OneDrive, Google Drive) or onto removable media, launching a proxy or HTTP server, altering firewall settings, enabling or disabling the task manager, and more.

It is possible that in the future, infected computers will be combined into a botnet for DDoS attacks. 



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster