"Once launched with administrator privileges, the Trojan loads into the memory of its process files containing cybercriminals' demands"
This sounds like it needs to run as root, is there any vulnerability involved and do I need to patch things?
Is it just a particularly crazy spam campaign that would somehow trick "website administrators" into running malware as root on their servers?