Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le juin 04, 2013, 20:02:59

Titre: [SecListe]Jumcar. Peruvian navy? Who could be behind it? [Third part]
Posté par: igor51 le juin 04, 2013, 20:02:59
Jumcar. Peruvian navy? Who could be behind it? [Third part]

We know that the family of malware called Trojan.MSIL.Jumcar and Trojan.Win32.Jumcar was developed in Peru with the primary aim of attacking Peruvian users. We also know that Chilean and Peruvian users have latterly been targeted as well. You can read more about this in our preliminary reports:

Jumcar. From Peru with focus on Latin America [First part]

Jumcar. Timeline, crypto, and specific functions [Second part]

During the initial investigation we saw a very striking series of strings from the source code of the first variants: "Armada Peruana". This is the Peruvian navy.

   

String "Armada Peruana" observed in decompilation of the Jumcar variant.

Source: Jumcar. Peruvian navy? Who could be behind it? [Third part] (http://www.securelist.com/en/blog/208195060/Jumcar_Peruvian_navy_Who_could_be_behind_it_Third_part)