Trojan Rootkit from a Worm

TrendLabs has received reports about a Trojan Rootkit that is being downloaded by a Worm. According to reports, this rootkit has been infecting systems since probably the 16th of March. The Trojan is said to search for or monitor different information regarding the activities of the users. It looks for things like Bank account numbers, Email login information, Insurance information, Airline logins, Passwords stored by browsers. Logs containing these things were found in one of the sites where the Trojan apparently uploads them.

More details will come your way as we further investigate on this matter.

Update(Obet, 22 March 2006 22:54:35)


We have acquired a sample for this and TrendMicro will detect it as TROJ_HEARSE.A

Click here for more info regarding the aforementioned malware.