This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how L0rdix is distributed, although it is likely that purchasers of the malware will deliver it via a number of vectors, including spam or phishing campaigns, drive-by downloads or watering hole attacks. Current versions of L0rdix contain a module for loading itself onto removable devices, providing a means of propagation once a device is infected.
L0rdix has several distinct capabilities including cryptocurrency mining, botnet creation, browser code injection and information theft. Once installed, it will collect a fingerprint of the affected system and connect to a command and control server, at which point it will initiate the removable drive infection module.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 17 February 2020 12:59 pm