Nivdort Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Nivdort AKA “BAYROB”, also detected as: Trojan-FHSS!7F4EA7834FBC (McAfee) and Troj/Nivdor-E (Sophos), is initially delivered in the form of a malicious.zip attachment in an email appearing to be from WhatsApp, Facebook or Amazon. It is primarily a password stealing malware, however it has also been known to steal personal details related to online shopping, banking and other social networking websites.
Nivdort acts in three cycles – Upon execution, the malware de-obfuscates the packed content, encrypted strings, Windows registry and API. In the second cycle, the malware copies itself with the name as decrypted in the first cycle, and then creates a service entry. It then goes on to create an auto start registry entry named similar to ‘C:\fjepsyrdasl\lczpilclxcd.exe’. This is to make sure its copy will be executed upon rebooting. During this process, the malware also disables the infected user’s firewall notifications from the Windows Security Centre.
Finally, the malware collects information such as the computer name, IP address, software and hardware configurations. It can also exfiltrate a user’s login credentials and credit card data by recording the keystrokes. When the malware has gathered this information, it connects to compromised domains such as the ones outlined below.
Once connected to the C2 (Command and Control) domain(s), it also has the ability to receive further instructions from the attacker to carry out other malicious activities on the infected machine.
Remediation steps
Last edited: 17 February 2020 12:50 pm