Home Malware Programs Trojans TSPY_ONLINEG.OMU

TSPY_ONLINEG.OMU

Posted: August 19, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 77
First Seen: August 19, 2013
OS(es) Affected: Windows

TSPY_ONLINEG.OMU is a password-stealing spyware program that also installs other malware onto your computer. Current payloads for TSPY_ONLINEG.OMU infections include backdoor Trojans, which allow remote attackers to control your PC and should be considered high-level security threats. Unusually, TSPY_ONLINEG.OMU does not install its second payload automatically; instead, TSPY_ONLINEG.OMU awaits a trigger keyed to the PC user attempting to access various industry-specific websites, which has led SpywareRemove.com malware experts to assume that TSPY_ONLINEG.OMU's backdoor attacks are intended to affect specific companies and ignore casual PCs. However, both professional and casual PCs are vulnerable to TSPY_ONLINEG.OMU's conventional spyware functions. Since neither aspect of TSPY_ONLINEG.OMU's attacks display any mentionable symptoms, anti-malware tools always should be used for finding and removing TSPY_ONLINEG.OMU.

TSPY_ONLINEG.OMU: a Spy with Something Extra Up Its Sleeves

TSPY_ONLINEG.OMU is a newly-developed version of TSPY_ONLINEG, which has been stealing gaming application passwords for several years. TSPY_ONLINEG.OMU monitors the infected PC's interaction with relevant online gaming sites and programs to steal your login information and also may disable some brands of anti-malware software. However, these functions also were found in previous versions of TSPY_ONLINEG; what makes TSPY_ONLINEG.OMU particularly interesting to SpywareRemove.com malware analysts is its capacity for assisting with the installation of a backdoor Trojan.

TSPY_ONLINEG.OMU's new backdoor-enabling function triggers whenever your browser loads an admin login page for specific South Korean industries, such as telecommunications, finance, advertising and (once again) gaming companies. TSPY_ONLINEG.OMU's backdoor component, the trojan BKDR_TENPEQ.SM, steals login data for these companies in a very similar way to how TSPY_ONLINEG.OMU steals game account information. In addition to targeting specific types of personal information, TSPY_ONLINEG.OMU's backdoor Trojan also includes a keylogger function that can record any typed information in general.

Keeping TSPY_ONLINEG.OMU from Hopping Through Your Browser to Your Hard Drive

TSPY_ONLINEG.OMU is distributed through legitimate but hacked South Korean sites that are forced to install TSPY_ONLINEG.OMU on their visitors' PCs through drive-by-download attacks. Fortunately, SpywareRemove.com malware researchers were able to confirm that all identified sites have been re-secured, but TSPY_ONLINEG.OMU's ongoing development makes the possibility of new attacks in the future a likely one. Anti-malware programs and browser security features in combination should be considered for blocking such attacks, and disabling exploitable script-based features (such as Java) is recommended.

Spyware like TSPY_ONLINEG.OMU carefully avoids showing any symptoms that would allow you to detect its presence. For this reason, SpywareRemove.com malware researchers find the continual deployment of anti-malware protection to be critical to detecting and removing TSPY_ONLINEG.OMU and other forms of spyware before any personal information may be stolen. As noted previously in this article, gaming passwords and user names are especially likely to be targeted, but TSPY_ONLINEG.OMU's new additions also should be considered capable of compromising professional business networks.

Loading...