The mistake that allowed researchers to put all clues together was the crook's lack of attention to detail, forgetting to delete the C&C server's ZIP installation package from one of the compromised Web servers used to host several C&C servers.
By looking at the files in this ZIP file and the C&C server source code, McAfee researchers quickly identified the server-side component of the ISR Stealer, a modified version of the Hackhound infostealer, an ancient piece of malware first spotted in 2009.
Crooks targeted companies that handled machinery parts
Researchers discovered that crooks used the IRS Stealer malware builder to create a p...
SOCIAL SHARE CARD GENERATOR