This backdoor also connects to a certain URL for its C&C prefs.

This is probably done so that users wont immediately suspect any malicious activities on their systems.

Article image

spot_img

source: www.techworm.net