Home Malware Programs Browser Hijackers Cloudnanoconnnection.info

Cloudnanoconnnection.info

Posted: December 30, 2014

Cloudnanoconnnection.info is a threatening domain that helps coordinate botnet attacks and distribute harmful software, with its latest payloads including a variant of an Alureon Trojan. PC threats in close association with Cloudnanoconnnection.info consist of spyware and other high-level threats that could install themselves and collect information without any symptoms. As usual, malware experts recommend all due browser-based precautions to block harmful content from this site, and using active anti-malware scans to delete threats that Cloudnanoconnnection.info could have downloaded onto your computer.

Cloudnanoconnnection.info: the Trojan Connection in Your Browser

Cloudnanoconnnection.info is one of a handful of websites that recently were confirmed to be involved in a YouTube-based threat campaign. This campaign leveraged fraudulent YouTube videos (for example, videos promoting the download of illegal game bots) along with an additional, fake Youtube domain to install their payloads. Once analyzed, those payloads were found to include variants of Trojan Zeus, a notorious banking Trojan.

Malware researchers and others in the industry traced the Trojan's relevant server information back to the rest of its botnet, including corrupted domains like winupdateservices.com, updatebackupserver.ru and, of course, Cloudnanoconnnection.info. Some of these sites also host threatening content of their own, including Cloudnanoconnnection.info's JavaScript-based exploits that try to install Alureon.

Alureon, like Zeus, includes keyboard-recording functions, monitoring your DNS settings and other spyware-based attacks that target and collect information, thereafter transferring it to its admins. Alureon also has long since been confirmed to abuse rootkit technology, which can provide stealth for its installation, allow it to launch without any visible program process and maintain persistence throughout some attempted removal techniques.

Detaching Yourself from a Threat Cloud

The seemingly Russia-based Cloudnanoconnnection.info campaign has shown characteristics typical to those of a well-thought-out and long-term threat campaign, using backup domains, multiple methods for threat distribution, and at least two complex Trojans. Cloudnanoconnnection.info and related sites also may display different behavior in a Virtual Machine environment, which could impede the efforts of PC security researchers to identify and protect against this campaign's threat installers. Disabling advanced browser features, like scripts, is a defense malware experts would heavily endorse, but you also should consider scanning any computer that has come into contact with Cloudnanoconnnection.info (or any associated site).

Cloudnanoconnnection.info also is a showcase for how third parties may use the wrongful motivations of others against them. Cloudnanoconnnection.info bolsters a campaign that installs high-level threats primarily via fake links for illegitimate products like aimbots, which can make any would-be cheater at a multiplayer video game a possible victim of Trojan infiltration. Related domains also make heavy use of fraudulent software updates, which gives Web surfers even more reasons than usual to download all of their software patches solely from reputable sources.

Loading...