• Home
  • About us
  • Contact us
  • DMCA
Forbes.llc
  • Home
  • Innovation
    • 5G
    • AI
    • Big Data
    • Cloud
    • Cloud 100
    • Consumer Tech
    • COP26
    • Cybersecurity
    • Enterprise Tech
    • Future Of Work
    • Games
  • Leadership
    • Careers
    • CEO Network
    • CFO Network
    • CHRO Network
    • CIO Network
    • CMO Network
    • Money
      • ETFs & Mutual Funds
      • Fintech
      • Hedge Funds & Private Equity
      • Investing
      • Investing Basic
      • Markets
      • Personal Finance
      • Premium Investing Newsletters
  • Forbes Digital Assets
    • Dashboard
    • Traded Assets
    • Research
    • Events
    • Crypto Portfolios
  • Business
    • Aerospace & Defense
    • Energy
    • Food & Drink
    • Hollywood & Entertainment
    • Manufacturing
    • Media
    • Policy
  • Small Business
    • Small Business Strategy
    • Enterprise Tech
    • Franchises
  • Lifestyle
    • Arts
    • Boats & Planes
    • Cars & Bikes
    • Dining
    • Real Estate
      • Commercial Real Estate
      • Residential Real Estate
      • Forbes Global Properties
      • Vetted
No Result
View All Result
  • Home
  • Innovation
    • 5G
    • AI
    • Big Data
    • Cloud
    • Cloud 100
    • Consumer Tech
    • COP26
    • Cybersecurity
    • Enterprise Tech
    • Future Of Work
    • Games
  • Leadership
    • Careers
    • CEO Network
    • CFO Network
    • CHRO Network
    • CIO Network
    • CMO Network
    • Money
      • ETFs & Mutual Funds
      • Fintech
      • Hedge Funds & Private Equity
      • Investing
      • Investing Basic
      • Markets
      • Personal Finance
      • Premium Investing Newsletters
  • Forbes Digital Assets
    • Dashboard
    • Traded Assets
    • Research
    • Events
    • Crypto Portfolios
  • Business
    • Aerospace & Defense
    • Energy
    • Food & Drink
    • Hollywood & Entertainment
    • Manufacturing
    • Media
    • Policy
  • Small Business
    • Small Business Strategy
    • Enterprise Tech
    • Franchises
  • Lifestyle
    • Arts
    • Boats & Planes
    • Cars & Bikes
    • Dining
    • Real Estate
      • Commercial Real Estate
      • Residential Real Estate
      • Forbes Global Properties
      • Vetted
Social icon element need JNews Essential plugin to be activated.
No Result
View All Result
Forbes LLC
No Result
View All Result

Researchers have found Packer used by multiple malware for six years to evade detection

by
January 31, 2023

[ad_1]

January 31, 2023Rabbi LakshmananThreat Detection / Malware

Malware evasion detection

A shellcode-based packer called trick gate It has been operating under the radar for over six years while enabling threat actors to deploy a wide variety of malware including TrickBot, Emotet, AZORult, Agent Tesla, FormBook, Cerber, Maze, and REvil.

Check Point Research’s Arie Olshtein called TrickGate a “master of disguise” and said, “TrickGate has been kept under the radar for years because it’s a game-changer. It’s changing,” he said.

TrickGate has been available as a service to other threat actors since at least late 2016, helping to hide payloads behind layers of wrapper code in an effort to evade security solutions installed on hosts. . Packers also act as crypters by encrypting malware as an obfuscation mechanism.

“Packers have a range of capabilities that allow them to appear as benign files, make them difficult to reverse engineer, and incorporate sandbox evasion techniques to evade detection mechanisms,” Proofpoint said December 2020. points to the moon.

However, with frequent updates to the commercial packer-as-a-service, TrickGate has been tracked under various names since 2019, including new loaders, Loncom, and NSIS-based crypters.

Malware evasion detection

Telemetry data collected by Check Point shows that the TrickGate attackers primarily singled out the manufacturing sector, and to a lesser extent the education, healthcare, government, and financial sectors.

The most common malware families used in attacks over the past two months included FormBook, LokiBot, Agent Tesla, Remcos, and Nanocore, with significant concentrations reported in Taiwan, Turkey, Germany, Russia, and China It has been.

Phishing emails containing malicious attachments or booby-trapped links are sent up the infection chain to download a shellcode loader that decrypts the actual payload and launches it into memory.

An analysis of the shellcode by an Israeli cybersecurity firm shows that “although it has been constantly updated, key functionality is present in all samples since 2016.” It is a sensitive part and has been observed in all TrickGate shellcodes.”

Did you find this article interesting?Please follow us twitter ○ and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

Next Post
FPT Featured on Bloomberg Television’s Global Media Technology Series “Beyond Innovation”

FPT Featured on Bloomberg Television's Global Media Technology Series "Beyond Innovation"

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Pet Insurance That Covers Pre-Existing Conditions – Forbes Advisor
  • Pet Insurance That Covers Pre-Existing Conditions – Forbes Advisor
  • Pros and Cons – Forbes Advisor
  • Home
  • About us
  • Contact us
  • DMCA

© 2022 forbes - Copyrights reserved by Forbes LLC.

No Result
View All Result
  • Home
  • Review
  • Apple
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security

© 2022 forbes - Copyrights reserved by Forbes LLC.