Description
The Fun/Troll functions in malware serve as a form of digital mischief, allowing attackers to toy with their victims by triggering a variety of benign but disruptive actions. These can range from opening and closing the CD-ROM drive, hiding the desktop icons, to disabling the start button or menu. More aggressive actions might include freezing the mouse cursor or turning the screen black. While these functions may seem playful or harmless at first glance, they often serve a dual purpose. First, they can distract the user or IT department, causing them to waste time on resolving seemingly trivial issues while the malware carries out its primary malicious activities undetected. Second, these actions can act as a smoke screen, generating a flurry of confusing system logs that make it more challenging to trace the malware's true activities. In this way, what appears to be 'trolling' can actually be a tactical maneuver within a broader attack strategy.
| Categories | Disruption, Alteration |
| Dangerousness | Low |
Existing Techniques
| Name | Associated Feature(s) | Has Snippet | Matching Sample |
|---|---|---|---|
Clipboard Disabling
|
Clipboard Manager, Fun / Troll Functions | 0 | |
Control CD/DVD Tray
|
Fun / Troll Functions | 10 |
Clipboard Disabling
Control CD/DVD Tray
ProRat 1.3
Nuclear RAT 1.0 Beta 5
Beast 2.06
ProRat 1.4
LanFiltrator 1.5 Beta III
ProRat 1.6
ProRat 1.8
Infector NG 2004 2.1.0
Optix Pro 1.33
Beast 2.07
CIA 1.3
ProRat 1.9
Y3K rat 2k5 RC 1.0
DARKMOON 4.11 / 4.11 Private Edition
Turkojan 3.0
Hav-Rat 1.2
Bandook 1.35
Nuclear RAT 2.1.0
Turkojan 4
Turkojan 4.0
SynRAT 2.1
Lost Door 3.0 Stable
SynRAT 4.0.1
PrjRAPTOR 1.8
Cerberus 1.0 Beta
Cerberus 1.01 Beta
Cerberus 1.02 Beta
Cerberus 1.03.4
Spy-Net 2.6
DarkComet RAT 1.3
Cerberus 1.03.5 Beta
DarkComet RAT 2.0 RC4
CyberGate 1.04.8
Lost Door 4.3.1
DarkComet RAT 2.0 RC7
Lost Door 5.1
Coolvibes 1 Update 8
Xtreme RAT 2.9
DarkComet RAT 5.3
DarkComet RAT 5.3.1
Lost Door 9.2 Aws