This Trojan arrives as attachment to email messages spammed by another malware or a malicious user.

This is a specially crafted Microsoft Excel document that takes advantage of a known software vulnerability to drop possibly malicious files. More information on the said vulnerability can be found here.

This vulnerability causes Microsoft Excel to crash and could potentially allow a remote user to take control of the affected system.

After successfully exploiting the said vulnerability, it drops and executes a certain file that Trend Micro detects as BKDR_POISON.EJ. As a result, routines of the dropped backdoor are also exhibited on the affected system.

Bookmark and Share