Home Malware Programs Backdoors BKDR_SIMBOT.ZTBD-PB

BKDR_SIMBOT.ZTBD-PB

Posted: May 13, 2014

Threat Metric

Threat Level: 8/10
Infected PCs: 7
First Seen: May 13, 2014
Last Seen: October 14, 2022
OS(es) Affected: Windows


BKDR_SIMBOT.ZTBD-PB is a backdoor Trojan that is a component of a malicious attack against government agencies that is based on email messages including malicious attachments. BKDR_SIMBOT.ZTBD-PB is connected with the targeted attacks regarding a remote code execution vulnerability in Word, that was being leveraged by cybercrooks. The Word vulnerability has been leveraged in targeted attacks against government agencies and an educational institution in Taiwan. The email messages allegedly come from a government employee. The operation against the educational institution relies on an email discussing free-trade issues. The file attached to the malicious emails is created to drop a backdoor Trojan, detected as BKDR_SIMBOT.ZTBD-PB, which allows cybercrooks to steal sensitive files from the affected organization.

Loading...