Home Malware Programs Malware Fort Disco

Fort Disco

Posted: August 16, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 1,757
First Seen: August 16, 2013
Last Seen: November 21, 2023
OS(es) Affected: Windows

Fort Disco is a backdoor Trojan that uses the infected PC's resources to compromise weak password-protected websites, particularly those for blogs and those that use prominent brands of content management systems (such as WordPress, Drupal or Joomla). Although Fort Disco's campaign still is relatively young, Fort Disco already has compromised tens of thousands of separate PCs. These PCs also are subjected to various attacks, such as browser hijacks that redirect your browser to sites hosting drive-by-download attacks that may install further malware. SpywareRemove.com malware experts rate Fort Disco as a meaningful threat to both poorly-protected websites and PCs alike, and recommend anti-malware software for removing Fort Disco when such actions are warranted.

Fort Disco: Dancing into Your PC with the Worst of Intentions

Fort Disco is a young but already-widespread backdoor Trojan that conducts various attacks against the computer Fort Disco compromises – as well as against separate websites. Fort Disco's remote C&C server provides the list of websites to target, which largely consist of blogs and similar websites that are most likely to use easily-cracked password protection. Rather than attempting to steal passwords directly from the website owners, Fort Disco merely brute-force attacks the passwords by attempting to 'guess' them. Accordingly, SpywareRemove.com malware experts warn that websites with poor password security (such as very short passwords, passwords without a good mix of alphanumeric characters or passwords with common phrases like 'password1') are highly at risk for being cracked by Fort Disco. The purpose behind Fort Disco's attacks against these sites is not yet known, but most likely involves forcing these sites to host malicious contact that may infect your normal website traffic through various software vulnerabilities.

However, while that's the end of Fort Disco's story thus far for the websites Fort Disco attacks, the computers compromised by Fort Disco will continue to have other issues. One significant component often installed by Fort Disco is a browser hijacker that currently redirects Internet Explorer to a site hosting the Styx Exploit Kit. This attack may be used to install other malware on an already-infected PC without many, if any, symptoms of the installation ever taking place. A second component also associated with Fort Disco is a modified WordPress add-on that most likely is used to load additional malicious content pulled from Tumblr blogs.

Dancing Your Computer Off of Fort Disco's Floor

While Fort Disco has an unusually colorful name, Fort Disco is equally dangerous to your PC as any similar backdoor Trojan. PCs most often targeted by Fort Disco's campaign are located in Mexico, Peru or the Philippine islands. In contrast, the websites typically victimized in Fort Disco attacks usually are based in Russia or neighboring countries. For the latter, strong password security is the most obvious protection against Fort Disco – while PC users who suspect that their PCs are compromised by Fort Disco should be quick to resort to anti-malware software.

Fort Disco should not be anticipated to leave any visible symptoms of its attacks and, like most backdoor Trojans, is designed with the intention of concealing itself from the casual observation of the PC user. In fact, only a happenstance error on the part of the criminals managing Fort Disco's C&C server logging activity allowed the majority of the details of Fort Disco's campaign to be brought to light so early in its progression. Since Fort Disco's attacks clearly are only just beginning to ramp up, SpywareRemove.com malware experts advise continued caution against Fort Disco attacks for the foreseeable future.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Fort Disco may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

Additional Information

The following URL's were detected:
fixchannel.site
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.