More and more malware and virus variants are being discovered that can bypass systems and operating system protection software, and even disguise themselves as legitimate applications to attack users.
More and more types of malware are able to bypass anti-malware software on operating systems.
Recently, Kaspersky's Global Research and Analysis Team (GReAT) discovered a new malware attack campaign by the notorious hacker group Lazarus targeting organizations around the world.
The GReAT team discovered a series of cyber attacks in which targets were infected with malware disguised as legitimate software, designed to encrypt web traffic with digital certificates.
However, organizations around the world continued to use the flawed software version even after the vulnerabilities were discovered and patched, creating an opportunity for the Lazarus group to carry out cyberattacks.
Cyber attackers control victims with the SIGNBT malware and use sophisticated evasion techniques to avoid detection. In addition to serving as the first point of infection, the malware also collects information to profile victims.
Further investigation revealed that the Lazarus malware repeatedly targeted the software vendor. The frequency of the attacks suggested the hackers’ motivation to disrupt the software supply chain and their determination to steal critical company source code.
“The ongoing attacks by the Lazarus group are a testament to the changing tactics and efforts of cybercriminals. They operate globally, targeting multiple industries with a variety of sophisticated methods of operation.
This shows that the threat is still present and requires everyone to be highly vigilant,” said Seongsu Park, head of security research at GReAT at Kaspersky.
According to Bkav Cyber Security Company, in the third quarter of 2023, new variants of many famous data-stealing viruses such as RedLine, Erbium... tend to use techniques to bypass anti-virus (AV) software by forging digital signatures and taking advantage of standard processes on computers in new attack campaigns.
Antivirus software only has the function of scanning normal files, easily ignoring programs with digital signatures. Taking advantage of this loophole, hackers create viruses that forge digital signatures to bypass these AVs. In just a few seconds, viruses can spread, steal data and send it to the server, causing incalculable damage to organizations and businesses.
Experts said Vietnam is among the countries targeted by the Erbium virus, along with the US, France, Colombia, Spain, Italy, India and Malaysia. Erbium is an information-stealing malware, distributed as a plug-in in game crack/cheat products to steal login information and cryptocurrency wallet information of victims.
Mr. Nguyen Tien Dat - General Director of Bkav's Malware Research Center - analyzed: "Viruses and their variants are becoming more and more sophisticated. Conventional anti-virus software will have difficulty dealing with them.
Users should choose to use copyrighted anti-virus solutions and software that use AI technology, integrate many protection functions, and receive regular updates and support from professional suppliers for comprehensive protection.
According to Tuoi Tre