Home » News » Malware » Anonymous is creating Guy Fawkes virus

Anonymous is creating Guy Fawkes virus

By Gina on November 14, 2011 | Malware, malware, Guy Fawkes malware, Anonymous, Facebook Anonymous is creating Guy Fawkes virus

It seems like a Security Outfit has found Guy Fawkes threat which acts like the virus that Anonymous was working on. This big hackers group claimed they are working on a malware which may be used to destroy Facebook.

Bitdefender says it identified a piece of scam which looks like and acts like the virus that Anonymous is creating. This peace of malware was called backdoor-Bifrose-AAJX by an e-threats analyst at Bitdefender Razvan Livintz.

Razvan Livintz commented: “The same day, it appeared on Facebook under the guise of a scam purporting to offer a "New Facebook Video Chat with Voice Features", according to its description (which, by the way, is in Arabic), if the unwary user follows a link and downloads an archive named scan_facebook.zip.“ „Once it compromises a system, Backdoor-Bifrose-AAJX does pretty much what the hacktivists say, which is: injects itself in IE process, provides a remote attacker unhindered access to the compromised system, records keystrokes and kills several processes of known anti malware solutions, if installed on the computer,“ he added.

However, malware does not have self copying characteristics, like the one Anonymous was talking about and it is not mentioned in the video that malware connects to a remote server in Egypt.

More Malware news

Danger! Facebook private messages and Instant Messengers are infected by worm

Danger! Facebook private messages and Instant Messengers are infected by worm

According to TrendLabs, infected messages are spreading on Facebook which contain a malicious link pointing to an archive file “May09-Picture18.JPG_www.facebook.com.zip”. Zipped archive itself has a file titled “May09-Picture18.JPG_www.facebook.com” and uses the extension “.com”. Malware within is able to terminate services and processes related to AV which quickly shuts down AV from detection or removal of the worm. This detected malware is named WORM_STECKCT.EVL. Read more.


News categories

Latest news

Related news