"The stealthiest file infector ever"
It seems that hackers are getting better at developing obfuscated and stealth mode malware code, as a security researcher with Symantec claims to have discovered the stealthiest file infector yet seen.
The trojan Backdoor.Prioxer, says Andrea Lelli, was received from a source that was also infected by the Koredos trojan, suggesting that there may be a link between the two pieces of malware.
"Why is Prioxer interesting? Well, at first glance it looks like a normal back door trojan, which, in fact, it is", he said, adding that the installer drops a bot and operates via internet relay chat to communicate with a command-and-control server, and infects a Windows DLL in order to `survive' a system reboot. What is curious, says Lelli, is that the infected files are completely invisible, despite the fact that Prioxer does not use a rootkit, nor does it use and executable code in kernel mode.