Password-Stealing 'Dorkbot' Worm Prowling Indian Cyberspace: CERT-In

Advertisement
By Press Trust of India | Updated: 2 February 2016 18:02 IST
Password-Stealing 'Dorkbot' Worm Prowling Indian Cyberspace: CERT-In
Cyber-security sleuths have alerted Indian Internet users against the malicious activity of an online virus called 'dorkbot' which perpetrates itself through social networking sites and steals sensitive personal data and passwords of a user.

The malware, a variant of online virus and worm, has been specifically seen affecting operating systems running on Windows in the recent past.

"It has been observed that the variants of malware named as 'dorkbot' targeting windows operating systems, are spreading.

"The malware belongs to the family of worms having backdoor functionality and spreads through various vectors including drive-by-download attacks, social networking sites and compromised websites with browser exploits via removable drives in the form of auto-run exploits or by means of malicious links in instant messaging chats or Internet relay chats," a latest advisory issued by the Computer Emergency Response Team of India (CERT-In) said.

Advertisement

The CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of the Indian Internet domain.

Advertisement

The deadly virus, with almost a dozen aliases, is capable of stealing sensitive information from infected machine including stored passwords, browser data, cookies and has a smart and lethal potential to take complete control of the affected system, it said.

The cyber-security agency said the malware can hide itself by over-writing, can collect system information such as OS (operating system) information, user privileges and apps installed on the system and can act to aid remote access of the infected machine to an attacker.

Advertisement

It destructs and infects a system by acquiring fake identities of Facebook, Skype or any other social media platform and lowers its immunity against a potential virus attack.

"To hide itself from detecting by anti-virus solutions, the malware injects its code into files like cmd.exe, ipconfig.exe, regedit.exe, regsvr32.exe, rundll32.exe, verclsid.exe and explorer.exe," the advisory said.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Cyber security, Dorkbot, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Saare Jahan se Accha, Tehran, Alien Earth, and More
  2. Tecno Spark Go 5G Launched in India With 6,000mAh Battery: See Price
  3. Nothing's Independence Day Sale: Discounts on Ear A, Buds 2 Plus and More
  1. Oppo K13 Turbo Pro With Built-in Cooling Fan Goes on Sale in India: Price, Offers
  2. Scientists Apply Stephen Hawking's Theory to Propose Detectable ‘Black Hole Morsels’ in Space
  3. China Advances Guowang Internet Constellation with Latest Satellite Launch
  4. ESA’s Mars Express Discovers Deep Valleys and Frozen Features Hinting at Mars’ Icy Past
  5. New Physics-Based Model Sheds Light on How Deep Neural Networks Learn Features
  6. Cosmic Visitor: 4.56-Billion-Year-Old Meteorite Strikes into Georgia Home
  7. Apollo 13 Commander Jim Lovell, Hero of Space Crisis, Dies at 97
  8. NASA Missions Uncover a Diverse Galaxy of Super-Earths, Raising New Questions About Planetary Evolution
  9. Isolated Now Streaming on Netflix: Everything You Need to Know
  10. Tehran Now Streaming on ZEE5: What You Need to Know About John Abraham Starrer High-Stakes Spy Thriller
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.