Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication
The mysterious Avatar rootkit, detected by ESET as Win32/Rootkit.Avatar, appears to reflect a heavy investment in code development, with an API and a SDK available, plus an interesting abuse of Yahoo Groups for C&C communications.
Aleksandr Matrosov and Anton Cherepanov • 01 May 2013