Malware of this family creates a file on an infected computer and copies malicious code to the file. Then the malware either runs the file, or creates a process and runs the file inside of the newly created process.
This malware also inserts itself into system processes and user processes. Once its “work” is complete, the malware deletes itself from the infected computer.
Geographical distribution of attacks by the Trojan-Dropper.Win32.Dapato family
Geographical distribution of attacks during the period from 17 February 2015 to 17 February 2016
Top 10 countries with most attacked users (% of total attacks)
* Percentage among all unique Kaspersky users worldwide who were attacked by this malware