This virus removes itself from infected devices in Russia and Ukraine

Security researchers from Doctor Web have published a report which states that the Andromeda RAT is uninstalling itself from infected devices which are in the countries Russian, Ukraine, White-Russia or Kazakhstan.

The Andromeda RAT is capable of collecting personal and financial information from infected devices, it also allows the cybercriminal / hacker to fully operate the infected device – meaning that the hacker can access the microphone, camera and data which is stored on the device.

It is not the first time that such thing has been noticed, an earlier report by CSIS stated that the MazarBOT acted like the same way as Andromeda RAT is doing in the countries mentioned above.

