Nov20
by
Jasper Pimentel (Advanced Threats Researcher)
Two new variants of Zlob–TROJ_ZLOB.BEV and TROJ_ZLOB.BEW–have just turned up. Once again, these new variants pose as codec installers that can be downloaded from legitimate-looking websites, moviecodec(dot)net and tvcodec(dot)com.


Don’t let the websites’ professional-looking design fool you. These websites do not contain any codec installers at all. Rather, the files that they are offering you for download are nothing more but TROJ_ZLOB variants.


