Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Scranos is delivered via cracked software downloads and illegitimate applications such as video players, drivers and anti-virus products. When opened, these applications install a signed rootkit driver, which is then used to maintain persistence and install further Scranos components.
Once installed, Scranos injects a downloader into a legitimate process which then communicates with a command and control server. It can then download various modules, providing it with a wide range of capabilities, including:
- stealing account and payment credentials from various popular services
- exfiltrating browsing history and cookies
- downloading and executing payloads
- displaying malicious adverts
- installing JavaScript adware or malicious extensions
- sending phishing messages
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:52 pm