This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
It is used in highly targeted campaigns, typically infecting less than a hundred devices per time, and as such it has only recently been identified and analysed by security researchers. At the time of publication it is unclear how InvisiMole is distributed, although there are unconfirmed reports indicating it is manually delivered to targeted systems. The small number of available samples of the malware - combined with the secrecy with which it has been created and deployed - make it difficult to accurately determine delivery mechanism.
InvisiMole is comprised of two modules, RC2FM and RC2CL, with both being capable of collecting user data. RC2FM, the smaller of the two modules, is able to record audio from a device's microphone, extract proxy browser settings and alter system files. The more advanced module, RC2CL, is able to:
- execute files and commands
- manipulate registry keys
- disable security services
- function as a proxy for command and control communications
- record audio and video
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:45 pm