Gumblar Trojan vanishes suddenly yet again

Peekaboo, malware style

A prolific variant of the Gumblar Trojan has performed another vanishing act, disappearing suddenly from malware figures gathered by Kaspersky Lab.

The company's statistics for April show that the Gumblar.x downloader was nowhere to be seen after being the most recorded piece of malware for February and March.

This is not the first time it has receded suddenly. After appearing in March 2009, Gumblar and subsequent variants went to the top of various company's malware league tables by October, at which point it started to die out. By January 2010 it had disappeared altogether before surging once again, seemingly from nowhere.

Gumblar and its variants are effective and versatile pieces of malware, recording 453,000 infections detected by Kaspersky during February alone. Its main means of spread is to use compromised websites to serve malicious browser scripts, which redirect the PCs of infected users. It can also be used to steal FTP and other logins for websites.

It is not clear why the malware appears and disappears so suddenly. It is unusual for malware other than Internet worms to surge and recede in this fashion, but it is likely to be a technique to keep some of the compromised websites beyond the range of easy detection.

"Kaspersky Lab advises that this should act as a warning sign, as this is typical of Gumblar.x's behaviour and is reminiscent of events reported by the company in February," says the company advisory.

More about: Kaspersky, Kaspersky Lab
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: gumblar, kaspersky labs, malware
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/21/clamwin-free-antivirus/

ClamWin Free Antivirus

ClamWin Free Antivirus is an open source GPL virus scanner for Microsoft Windows 7 / Vista / XP / Me / 2000 / 98 and ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia