Home Malware Programs Backdoors Backdoor.APT.Aumlib

Backdoor.APT.Aumlib

Posted: August 13, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 37
First Seen: August 13, 2013
OS(es) Affected: Windows

Backdoor.APT.Aumlib is a backdoor Trojan used in targeted attacks, typically against government agencies and companies involved in the North American telecommunications industry. While Backdoor.APT.Aumlib has been used in attacks against such specific organizations for several years, until now, its last update was in 2011 – with this newest update indicative of its continued use in targeted cyber attacks. Backdoor.APT.Aumlib allows criminals to access your PC by opening a backdoor connection between itself and a remote server, from which point a criminal may perform a variety of attacks against your PC. In light of the past infection vectors of targeted Trojan attacks like Backdoor.APT.Aumlib, SpywareRemove.com malware researchers especially caution potential victims to be careful about opening unusual e-mail attachments and recommend the use of anti-malware software for detecting or removing Backdoor.APT.Aumlib whenever it's necessary.

Backdoor.APT.Aumlib: When a Few Tweaks Make an Old Trojan New

Along with IXESHE – a similar backdoor Trojan also commonly found in targeted backdoor campaigns – Backdoor.APT.Aumlib has been in use in targeted attacks for some time but has recently received significant updates. These updates are designed for concealing Backdoor.APT.Aumlib from being identified by old threat databases; partially encoded Command & Control server communications may prevent outdated anti-malware tools from identifying Backdoor.APT.Aumlib correctly – or at all. Besides its new stealth feature, the most current version of Backdoor.APT.Aumlib still is similar to old versions of Aumlib.

SpywareRemove.com malware experts stress that PCs compromised by Backdoor.APT.Aumlib Trojans are effectively under the control of a remote attacker, who may steal information, install various other forms of malware, infect other PCs through local networks or downgrade your PC's security features. These attacks are far from unusual for any backdoor Trojan, although Backdoor.APT.Aumlib does have the additional headline-worthiness of being used in attacks against specific Western companies and government institutions. Therefore, casual PC users shouldn't expect to encounter Backdoor.APT.Aumlib in the wild.

Tracking Where the Backdoor.APT.Aumlib Campaign Goes from Here

The criminal group of hackers responsible for distributing and managing Backdoor.APT.Aumlib are believed to be Chinese in origin and clearly are ramping Backdoor.APT.Aumlib and Ixeshe up for continued use in the coming months. SpywareRemove.com malware experts stress that most targeted attacks like Backdoor.APT.Aumlib's campaigns usually are initiated through carefully-crafted e-mail messages with malicious file attachments. Deleting suspicious files without opening them or, alternately, scanning them with updated anti-malware products should be considered mandatory for protecting a vulnerable PC from Backdoor.APT.Aumlib.

Along with that, updating your security and anti-malware software always is required by SpywareRemove.com malware experts but is particularly relevant in the case of Backdoor.APT.Aumlib. Backdoor.APT.Aumlib's latest update specifically is intended to evade previous anti-malware signatures that would be able to detect Backdoor.APT.Aumlib's old versions, and having an anti-malware product that isn't updated regularly shouldn't be thought of as a foolproof defense against professionally-managed PC threats like Backdoor.APT.Aumlib.

Technical Details

Additional Information

The following URL's were detected:
get-positive.com
Loading...