Jump to content
dicksi

Pony Loader 2.0 updated to steal crypto-currencies

Recommended Posts

Posted

The criminals attempting to sell the source code for Pony 2.0 advertise the bitcoin programs that are targeted in the updated version. Damballa has verified the following list of bitcoin software in Pony version 2.0:

Electrum, MultiBit, Litecoin, Namecoin, Terracoin, Bitcoin Armory, PPCoin (Peercoin), Primecoin, Feathercoin, NovaCoin, Freicoin, Devcoin, Frankocoin, ProtoShares, MegaCoin, Quarkcoin, Worldcoin, Infinitecoin, Ixcoin, Anoncoin, BBQcoin, Digitalcoin, Mincoin, Goldcoin, Yacoin, Zetacoin, Fastcoin, I0coin, Tagcoin, Bytecoin, Florincoin, Phoenixcoin, Luckycoin, Craftcoin, Junkcoin and the original Bitcoin client.

In addition, the sellers are marketing additional features and 'upgrades' as follows - Russian to English translation:

[+] Implemented collection of Ya.Browser passwords, FTP Disk, new versions of Opera (code-based Chrome)

[*] When the program on behalf of the user SYSTEM (service Windows) will now run the loader file as an active session (logged on) Users

[*] Improved collect passwords Firefox, is no longer dependent on the availability of libraries SQLite3

[+] Optional redundant bootloader mode: if successfully loaded the first file – the rest will be skipped

[+] Added option to disable the collection of passwords (just leave the loader)

[-] Fixed processing SQLite3 files for Chrome / Firefox containing 48 bit integers

[-] Fixed a serious bug in several functions, which could lead to errors in the collection of passwords and reach program

Implemented instantaneous decoding of saved passwords for the following programs:

....

See original postings on pastebin.com here:

Pony 2.0 botnet - Pastebin.com

Pony 2 stealer sell JID: pony2@swissjabber.ch

articol complet

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...