More

    Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc




    • Trend Micro has spotted Earth Preta dodging antivirus in new attack
    • The malware deployment checks to see if ESET antivirus is installed
    • Malware hijacks legitimate processes to inject malicious code

    A Chinese hacking group tracked as Earth Preta and Mustang Panda has been spotted using the Microsoft Application Virtualization Injector to dodge antivirus software by injecting malicious code into legitimate processes.

    New research from Trend Micro’s Threat Hunting team revealed how the group has also been using Setup Factory, a third-party Windows installer builder, to drop and executive malicious payloads.

    https://cdn.mos.cms.futurecdn.net/SDMQUu5885sMgU6txC7EDZ-1200-80.jpg



    Source link
    benedict.collins@futurenet.com (Benedict Collins)

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img