We Watched the Victims in Real Time (opens in new tab)
The most unsettling part of this research wasn’t the malware. It was watching real people get robbed, live. While analyzing the campaign, LMG connected to the attackers’ command-and-control server the same way an infected machine would. We didn’t run the malware and we didn’t touch anyone’s data — but the server, with no authentication at all, immediately began broadcasting its list of active victims. …
Read the original article