Good Cop Evil Corp – protecting yourself from the Dridex virus
Posted: Thursday, October 15, 2015
A virus which has helped cyber criminals steal over £20m from UK bank accounts has been making headlines this week following the arrest of a member of the ‘Evil Corp’ gang that wrote it.
Good Cop, ‘Evil Corp’
The flow of this malware has been interrupted and could soon stop thanks to a successful crackdown by the FBI and Britain’s National Crime Agency (NCA) amongst others. But, in the meantime, the threat remains present. So what is Dridex and what can you do to stay safe?
What is Dridex?
Dridex (also known as Bugat and Cride) is a strain of malware authored by an Eastern European gang calling themselves ‘Evil Corp’. It is designed to eavesdrop on victim’s computers in order to steal personal login details (usernames and passwords), with the eventual aim of hacking into bank accounts and stealing cash.
How does it spread?
The virus is spread through emails, typically containing an infected Microsoft Office file, which claims to be something legitimate such as an invoice or a delivery note from a supplier. When opened, the infected file, usually a Word doc or Excel worksheet, downloads a small embedded program (a ‘macro’) which installs itself onto your PC.
What can I do to stay safe?
Protecting yourself against the Dridex virus is no different to protecting against any other form of malware attack and our advice to users is in line with best practice we have laid out in previous blogs.
We recommend that Windows users should always be running an up-to-date, reputable antivirus program on their machines, as this should be able to flag infected attachments before users are tempted into opening them.
Additionally, we would advise avoiding opening emails or attachments from unrecognised senders. You might also consider disabling macros in Microsoft Office or at least setting them to request permission before running. Please do not hesitate to call Utilize support on 0333 006 9060 should you should you have any questions relating to Dridex or any other virus.
What is the NCA’s advice to UK internet users?
Members of the public are reminded they should be vigilant and not open documents in emails, or click on links, if they are unexpected or if they are unclear about its origin.
If any internet users think they have lost money through malware such as Dridex, they should report their concerns to Action Fraud and alert their respective banks.











