<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; W32.Gammima.AG</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/w32gammimaag/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Chinese hacker malware infects International Space Station?</title>
		<link>http://www.thedarkvisitor.com/2008/08/chinese-hacker-malware-infects-international-space-station/</link>
		<comments>http://www.thedarkvisitor.com/2008/08/chinese-hacker-malware-infects-international-space-station/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 10:31:53 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[International Space Station]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[W32.Gammima.AG]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=456</guid>
		<description><![CDATA[Breaking news is that the International Space Station has been infected by the W32.Gammima.AG trojan. The trojan is also referred to as the kavo.exe virus and is designed to gather information on ten online games: ZhengTu Wanmi Shijie or Perfect World Dekaron Siwan Mojie HuangYi Online Rexue Jianghu ROHAN Seal Online Maple Story R2 (Reign [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/spacestation.jpg"><img class="size-medium wp-image-457 aligncenter" title="spacestation" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/spacestation.jpg" alt="" /></a></p>
<p>Breaking news is that the <a href="http://www.telegraph.co.uk/connected/main.jhtml?xml=/connected/2008/08/27/dlvirus127.xml">International Space Station has been infected by the W32.Gammima.AG trojan</a>.  The trojan is also referred to as the kavo.exe virus and is designed to gather information on <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-082706-1742-99&amp;tabid=2">ten online games</a>:</p>
<p>ZhengTu<br />
Wanmi Shijie or Perfect World<br />
Dekaron Siwan Mojie<br />
HuangYi Online<br />
Rexue Jianghu<br />
ROHAN<br />
Seal Online<br />
Maple Story<br />
R2 (Reign of Revolution)<br />
Talesweaver</p>
<p>Not familiar with all the games but most are Chinese or Korean.   Chinese hackers specialize in stealing online gaming information.  <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-082706-1742-99&amp;tabid=2">Symantec</a> also offers up this bit in its writeup:</p>
<blockquote><p>The worm ends the Matrix Password process if it finds a dialog box with the following characteristics:<br />
Title: MatrixPasswordDlg<br />
Message: Warning! (In Chinese characters)</p></blockquote>
<p>Will check more into the origin of this malware later today but all indicators suggest that it could be Chinese.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/08/chinese-hacker-malware-infects-international-space-station/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

