When BREDOLAB entered the threat landscape several months ago, it was initially thought of as a common downloader (that downloads executable files) designed for malware infection only. However, Trend Micro researchers noticed a sudden increase in its activities by August 2009. This made our researchers delved more on the inner workings and behaviors of BREDOLAB.
Our analysis then observed BREDOLAB’s connections to two notorious malware families, FAKEAV and ZBOT/ZeuS. The samples always include the aforementioned malware in its download repertoire. Adding BREDOLAB in their long list of carriers, these malware families are mostly focused on information and financial theft.
BREDOLAB also exhibited certain similarities with another well-known botnet, PUSHDO in terms of downloading routines. This led our threat researchers to believe that the cybercriminals behind PUSHDO and BREDOLAB are the same.
Trend Micro’s Senior Threat Researcher David Sancho has written an in-depth analysis of this new threat. Read it here: You Scratch My Back…BREDOLAB’s Sudden Rise in Prominence.
Post from: TrendLabs | Malware Blog - by Trend Micro
BREDOLAB Revealed!
