Dimnie Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Dimnie the reconnaissance and espionage trojan has the ability to harvest credentials, download sensitive files, take screenshots, log keystrokes on 32-bit and 64-bit architectures, download additional malware on infected systems and self-destruct when ordered to. The malware has largely flown under the radar for the past three years due to its stealthy command and control methods.
The attack begins by spamming the email inboxes of users with fake, infected job offers. The messages used in this campaign attempt to trick the victims into running an attached malicious .doc file. The doc file contains embedded macro code, which if allowed, executes a PowerShell command to download and install the Dimnie trojan – malware that can be controlled remotely, enabling attackers to hijack infected PCs and install additional malware.
Dimnie is not new; it first appeared in early 2014, but the use of stealthy command and control (C&C) methods in the new version of the Dimnie malware helped the threat remain unnoticed until this year.
Remediation advice
To prevent and detect a Trojan infection, ensure that:Remediation steps
Last edited: 17 February 2020 11:29 am