Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Unlike most dropper-as-a-service malware, ProtonBot appears to be sold as a pre-packed sample, complete with command and control (C2) panel, directly to attackers.
At the time of publication, ProtonBot has only been observed being distributed via spam campaigns. However, each attacker may choose their own delivery method, raising the possibility of other vectors being used in the future.
Once delivered, a small script is used to extract and decrypt the primary ProtonBot module, which will then connect to an attacker-specified C2 server before collecting system information. It will then download and install any additional modules or payloads. ProtonBot can also execute batch, PowerShell and Visual Basic script as well as HTML code.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:45 pm