Login Register






Windows Malware Wants To Add Your PC To A Botnet filter_list
Author
Message
Windows Malware Wants To Add Your PC To A Botnet #1
Greetings to all,

Yet another Insecurity of the Windows platform, this time on a larger scale. Do take the time to read the nature of the malware- It's attack vector Is quite Impressive.

Quote:A new malware campaign is roping systems into a botnet and providing the attackers with complete control over infected victims, plus the ability to deliver additional payloads, putting the victims' devices at risk of Trojans, keyloggers, DDoS attacks and other malicious schemes.

The malware comes equipped with three different layers of evasion techniques which have been described by the researchers at Deep Instinct who uncovered the malware as complex, rare and "never seen in the wild before".

The sophisticated nature of the botnet suggests that those behind it aren't amateurs, with Mylobot incorporating various techniques to avoid detection.

They include anti-sandboxing, anti-debugging, encrypted files and reflective EXE, which is the ability to execute EXE files directly from memory without having them on the disk. The technique is not common and was only uncovered in 2016, and makes the malware ever harder to detect and trace.

On top of this, Mylobot incorporates a delaying mechanism which waits for two weeks before making contact with the attacker's command and control servers -- another means of avoiding detection.

Source.
[Image: AD83g1A.png]

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #2
One day, anti-malware would just become pointless because of the new technology being built.

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #3
(06-21-2018, 10:52 AM)Mimiakira Wrote: One day, anti-malware would just become pointless because of the new technology being built.

The keywords are "one day".

As much as I hope It's true, I don't see It happening anytime soon.
[Image: AD83g1A.png]

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #4
(06-21-2018, 09:34 AM)mothered Wrote:
Quote:The malware comes equipped with three different layers of evasion techniques which have been described by the researchers at Deep Instinct who uncovered the malware as complex, rare and "never seen in the wild before".

The sophisticated nature of the botnet suggests that those behind it aren't amateurs, with Mylobot incorporating various techniques to avoid detection.

They include anti-sandboxing, anti-debugging, encrypted files and reflective EXE, which is the ability to execute EXE files directly from memory without having them on the disk. The technique is not common and was only uncovered in 2016, and makes the malware ever harder to detect and trace.

On top of this, Mylobot incorporates a delaying mechanism which waits for two weeks before making contact with the attacker's command and control servers -- another means of avoiding detection.

Doesn't sound like anything new. Any decent malware would have everything that this has, heck even public RATs used by skids have some forms of anti-emulation, anti-VM, anti-analysis, anti-whatever and file obfuscation via encryption and compression. I highly doubt reflective executable injection is something as recent as 2016 and it's not exactly the hardest thing to do - any decent author would know how to do this. Delaying mechanisms are also quite common and definitely not something new.

I've only spent a few years self-studying malware and I can implement all of the above features without too much effort. Also, it seems that this "new malware" hasn't popped up in Bleeping Computer yet so I'm still pretty skeptical about this. Yawn

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #5
Kali can run from memory or live cd, live Ram stick...too? Is that kinda the same idea here? Different technologies? If so, how is that uncommon? or did they mean uncommon in the - its used in this way ie hostile actions.
(This post was last modified: 07-17-2018, 04:26 AM by singlehandlogic.)

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #6
(06-21-2018, 10:52 AM)Mimiakira Wrote: One day, anti-malware would just become pointless because of the new technology being built.

Agree.

In fact, In terms of sophisticated attacks, It Is somewhat pointless nowadays. For the average malware that's been community property for a while and Is defined In (example) MBAM's database definitions, It serves It's purpose- to some degree.
[Image: AD83g1A.png]

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #7
On top of this, Mylobot incorporates a delaying mechanism which waits for two weeks before making contact with the attacker's command and control servers -- another means of avoiding detection.

Interesting 1

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #8
(06-21-2018, 09:34 AM)mothered Wrote: Greetings to all,

Yet another Insecurity of the Windows platform, this time on a larger scale. Do take the time to read the nature of the malware- It's attack vector Is quite Impressive.

Quote:A new malware campaign is roping systems into a botnet and providing the attackers with complete control over infected victims, plus the ability to deliver additional payloads, putting the victims' devices at risk of Trojans, keyloggers, DDoS attacks and other malicious schemes.

The malware comes equipped with three different layers of evasion techniques which have been described by the researchers at Deep Instinct who uncovered the malware as complex, rare and "never seen in the wild before".

The sophisticated nature of the botnet suggests that those behind it aren't amateurs, with Mylobot incorporating various techniques to avoid detection.

They include anti-sandboxing, anti-debugging, encrypted files and reflective EXE, which is the ability to execute EXE files directly from memory without having them on the disk. The technique is not common and was only uncovered in 2016, and makes the malware ever harder to detect and trace.

On top of this, Mylobot incorporates a delaying mechanism which waits for two weeks before making contact with the attacker's command and control servers -- another means of avoiding detection.

Source.

Dont use a-m programmes. In the main your hands.

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #9
(11-02-2018, 04:39 PM)Faradenda Wrote:
(06-21-2018, 09:34 AM)mothered Wrote: Greetings to all,

Yet another Insecurity of the Windows platform, this time on a larger scale. Do take the time to read the nature of the malware- It's attack vector Is quite Impressive.

Quote:A new malware campaign is roping systems into a botnet and providing the attackers with complete control over infected victims, plus the ability to deliver additional payloads, putting the victims' devices at risk of Trojans, keyloggers, DDoS attacks and other malicious schemes.

The malware comes equipped with three different layers of evasion techniques which have been described by the researchers at Deep Instinct who uncovered the malware as complex, rare and "never seen in the wild before".

The sophisticated nature of the botnet suggests that those behind it aren't amateurs, with Mylobot incorporating various techniques to avoid detection.

They include anti-sandboxing, anti-debugging, encrypted files and reflective EXE, which is the ability to execute EXE files directly from memory without having them on the disk. The technique is not common and was only uncovered in 2016, and makes the malware ever harder to detect and trace.

On top of this, Mylobot incorporates a delaying mechanism which waits for two weeks before making contact with the attacker's command and control servers -- another means of avoiding detection.

Source.

Dont use a-m programmes. In the main your hands.

What do you mean, particularly with the latter part of your comment?
[Image: AD83g1A.png]

Reply

RE: Windows Malware Wants To Add Your PC To A Botnet #10
Just have a good antivirus and I think it will be okay.

Reply