Castov

Description

Also in 2013, researchers spotted a piece of malware called Castov (Downloader.Castov and Infostealer.Castov) targeting South Korean financial institutions and their customers. In these attacks, which are also believed to originate from Lazarus, Castov was used to steal passwords, account details, and digital certificates from the computers it infected. Castov (Trojan.Castov) was also used in further DDoS attacks against South Korean targets in June 2013.

Names

Name
Castov

Category

Malware

Type

  • Credential stealer
  • Info stealer

Information

Other Information

Uuid

0bbb5c6f-27ba-47bc-a37a-55c3914df115

Last Card Change

2020-04-20