February 11, 2020 By David Bisson 2 min read

Security researchers recently spotted KBOT malware, the first “living” computer virus they’ve discovered in years.

Kaspersky Lab explained that it hadn’t seen a new computer virus in the past few years, but that changed when it observed KBOT injecting malicious code into Windows executable code as a means of spreading. The security firm explained that the malware functions as a “living virus” in that sense.

Upon further investigation, Kaspersky’s researchers noted that the malware penetrates a user’s computer via the web, the local network or an infected piece of external media. Once launched, the malware gains a foothold on the system by writing itself to Startup and the Task Scheduler. The virus then attempts to deploy web injects for the purpose of stealing a user’s personal and banking data. It also tried to load additional stealer modules designed to target a user’s logins, cryptocurrency wallet data and other information with the intent of sending this stolen data to its command-and-control (C&C) server.

A Look Back at Possible Earlier KBOT Activity

Kaspersky Lab’s researchers weren’t the first to discover a malware sample identified as KBOT. On the contrary, NoVirusThanks spotted a similar C&C bot all the way back in November 2012. In May 2016, Cofense detected several new phishing campaigns distributing Bolek, sophisticated malware derived from repurposed “Kbot” source code from Carberp. A few months after that, in October, BitSight observed that Bolek had begun targeting users in Ukraine and Poland.

The recent KBOT sample discovered by Kaspersky represents a more serious threat than these past possible iterations, however. According to the researchers, the threat “is able to spread quickly in the system and on the local network … significantly slows down the system through injects into system processes, enables its handlers to control the compromised system through remote desktop sessions, steals personal data, and performs web injects for the purpose of stealing users’ bank data.”

How Organizations Can Defend Against KBOT

Security professionals can help prevent a KBOT infection by using artificial intelligence (AI) and machine learning to increase their visibility into potentially suspicious behaviors on the network. Companies should also implement a multifaceted security strategy that controls access to enterprise resources and continuously monitors business-critical endpoints for malicious activities.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today