InvisiMole spyware turns affected computer into video camera

Page 1 of 2 12 LastLast

    InvisiMole spyware turns affected computer into video camera


    Posted: 11 Jun 2018
    This is the modus operandi of the two malicious components of InvisiMole. They turn the affected computer into a video camera, letting the attackers see and hear what’s going on in the victim’s office or wherever their device may be. Uninvited, InvisiMole’s operators access the system, closely monitoring the victim’s activities and stealing the victim’s secrets.

    Our telemetry indicates that the malicious actors behind this malware have been active at least since 2013, yet the cyber-espionage tool was never analyzed nor detected until discovered by ESET products on compromised computers in Ukraine and Russia.

    The campaign is highly targeted – no wonder the malware has a low infection ratio, with only a few dozen computers being affected.

    InvisiMole has a modular architecture, starting its journey with a wrapper DLL, and performing its activities using two other modules that are embedded in its resources. Both of the modules are feature-rich backdoors, which together give it the ability to gather as much information about the target as possible.

    Extra measures are taken to avoid attracting the attention of the compromised user, enabling the malware to reside on the system for a longer period of time. How the spyware was spread to the infected machines is yet to be determined by further investigation. All infection vectors are possible, including installation facilitated by physical access to the machine...

    Conclusion

    InvisiMole is fully-equipped spyware whose rich capabilities can surely compete with other espionage tools seen in the wild.

    We can only wonder why the authors decided to use two modules with overlapping capabilities. One might think the smaller module, RC2FM, is used as an initial reconnaissance tool, while the bigger RC2CL module is only run on interesting targets. This is, however, not the case – both of the modules are launched simultaneously. Another possible explanation is that the modules might have been crafted by various authors and then bundled together to provide the malware operators a more complex range of functionalities.

    The malware uses only a few techniques to avoid detection and analysis, yet, deployed against a very small number of high-value targets, it was able to stay under the radar for at least five years....


    Read more: InvisiMole spyware hunting for secrets while staying deep in the shadows

    See also: malware-ioc/invisimole at master - eset/malware-ioc - GitHub
    Brink's Avatar Posted By: Brink
    11 Jun 2018



  1. Posts : 9,600
    Win 7 Ultimate 64 bit
       #1

    And people wonder why I remove the webcam software on my notebook and put tape over the camera lens.
      My Computer


  2. Posts : 72,037
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #2

    Surprise, you're on Candid Camera.
      My Computer


  3. Posts : 6,021
    Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
       #3

    Brink said:
    Surprise, you're on Candid Camera.
      My Computer


  4. Posts : 176
    Win 7 Home Prem x64 SP1
       #4

    I use a simple plastic lens blocker to physically cover my lens. Sometimes the simplest solution (low tech) is the best solution.
      My Computer


  5. Posts : 31,249
    Windows 11 Pro x64 [Latest Release and Release Preview]
       #5

    Erm, Russia and the Ukraine affected - perhaps it's just Vladimir checking next years election results
      My Computers


  6. Posts : 310
    windows 7 ultimate x32
       #6

    how is protecting/covering lens going to stop users from accessing your content ? I don't use any protection but my system notifies me when ever webcam gets turned on. My laptop is only open when I am working other time it just sleeps face down when I'm not. Only thing they will be able to access is dark keyboard, lol !
      My Computer


  7. Posts : 176
    Win 7 Home Prem x64 SP1
       #7

    goodlad said:
    how is protecting/covering lens going to stop users from accessing your content ? I don't use any protection but my system notifies me when ever webcam gets turned on. My laptop is only open when I am working other time it just sleeps face down when I'm not. Only thing they will be able to access is dark keyboard, lol !
    It won't. But the OP was about surreptitiously turning on your camera to spy on you and the goings on in the surrounding area. For desktop users a lens cover will protect from that. When you close your laptop you are effectively using a lens cover.
      My Computer


  8. Posts : 1,797
    Win 7 Ultimate, Win 8.1 Pro, Linux Mint 19 Cinnamon (All 64-Bit)
       #8

    Not a big webcam or skype user, so I rarely use a webcam these days. When it's not being used on my desktop systems I keep it unplugged, and I don't even have the drivers enabled or software installed for it on my laptop.
      My Computer


  9. Posts : 1,849
    Windows 7 pro
       #9

    Because I'm paranoid my integrated camera is disabled in devise manager and the USB one is disconnected.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:36.
Find Us