Godzilla Loader Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
As it is sold directly to attacker for use in their campaigns, Godzilla Loader can be delivered in whichever way they see fit. However, at the time of publication, there are only unconfirmed reports indicating it is being delivered in spam campaigns as an embedded EXE file contained within Microsoft Office documents.
Once installed, Godzilla Loader will connect to a command and control server specified by the attacker and generate registry entries to maintain persistence. It will then delete Volume Shadow Copies before downloading and installing the intended payload. Newer versions of Godzilla Loader include modules for keylogging, credential theft and network propagation.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:43 pm