Home Malware Programs Backdoors Backdoor.Mishko

Backdoor.Mishko

Posted: October 6, 2016

Threat Metric

Threat Level: 6/10
Infected PCs: 64
First Seen: October 6, 2016
OS(es) Affected: Windows


Backdoor.Mishko is a backdoor Trojan that may provide remote attackers with the ability to execute corrupted code on the infected machine. Judging by the results found on the Web, as well as if we take into account that the threat's name 'Mishko', it is very likely that this backdoor Trojan might be widely spread in Russia and other countries that are part of the CIS (Commonwealth of Independent States). There's no accurate information regarding the distribution methods and tricks that might be used to help Backdoor.Mishko reaches the computers of users, but other threats of this type are known to rely on e-mail spam, pirated software, fake downloads, and other dubious tricks that may mislead users into believing that they are about to run a reputable piece of software.

Infections with Backdoor.Mishko should not be underestimated because this threat can cause a lot of damage if it isn't stopped on time. Unfortunately, users whose machines have been infected with Backdoor.Mishko may often see no obvious signs or symptoms that may point to a threat infection. This is why it is important to use a reputable anti-malware suite that has the necessary active and passive protection modules to keep their browsing sessions safe from infectious files.

Once Backdoor.Mishko infiltrates a computer successfully, it may apply several changes to the file system and Registry entries to ensure that the infection will persist after the computer has been shut down. Backdoor.Mishko uses the file 'sysmgr.exe' to inject its harmful payload, and it also creates several configuration files in the %TEMP% folder. The backdoor Trojan then connects to remote servers that may be used to execute commands on the victim's machine remotely.

Loading...