Advanced Malware Takes Unique Steps to Hide Itself
Researchers have discovered a new type of malware that uses several advanced strategies to prevent you from detecting it. Those strategies include tracking user mouse usage and hiding malicious files.
The malware, which is being called Trojan.APT.BaneChant, was recently discovered by researchers at security firm FireEye. The malware reportedly spreads through an infected Microsoft Word document attached to emails.
So far, BaneChant has mostly been seen overseas. "We suspect that this weaponized document was used to target the governments of Middle East and Central Asia," noted FireEye researcher, Chong Rong Hwa. (Source: pcworld.com)
Malware Built to Detect Human Behaviour
Here's how BaneChant works: once the malware has been downloaded and installed on a system, it attempts to figure out if the operating environment is a virtualized one.
A virtualized operating environment might include an antivirus sandbox or an automated malware analysis system. To see if this kind of system is being used, BaneChant checks for mouse activity.
The advantage of this system: by waiting to confirm that a human is using the system (it's more likely that a human will click multiple times), BaneChant reduces the chance that it will be detected and removed. (Source: infosecurity-magazine.com)
Hwa says this kind of tactic has been used before, but typically involved waiting for a single mouse click. BaneChant takes things a step further by checking for at least three mouse clicks before moving on to the second part of the attack stage.
Malware Hides URL, Malicious Image File
In addition to the mouse checking, BaneChant communicates by manipulating its URL so that the system cannot detect that a program is connecting to a blacklisted service for further instructions.
Finally, BaneChant uses a malicious .JPG image file called GoogleUpdate.exe in the "C:\ProgramData\Google2\" folder. A link to that file in the user's start-up folder ensures that the malware is executed every time the system is rebooted.
By using the name 'GoogleUpdate,' BaneChant further dupes users into thinking it's a harmless program.
Hwa says these tricks make BaneChant a very advanced form of malware designed to evade human detection.
He adds that, once installed, BaneChant communicates with a central command and control server. It then passes along critical system information to that server.
From there, BaneChant can also download and execute new files on the infected system.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.