Customized, stealthy malware growing pervasive

It's no secret that the goal of modern malware writers is to create attack software that is stealthy and flows undetected for as long a period of time as possible. What's increasingly startling, however, is how pervasive custom malware has become as part of traditional attacks.

"The advanced attack is getting more pervasive," says Shawn Moyer, managing principal at security services firm Accuvant Labs. "In our engagements and my conversations with peers we are dealing with more organizations that are grappling with international infiltration," he says. "Every network we monitor, every large customer, has some kind of customized malware infiltrating data somewhere. I imagine anybody in the global 2,500 has this problem."

Malware history lesson: 40 years after the first computer virus

Not all of the code slipping on by security defenses is customized malware. Consider the Prioxer backdoor Trojan discovered by Symantec. The Trojan does many of the things a typical Trojan would do, such as drop a .dll file, operate command and control through IRC channels. However, because of some trickery between the cached version of the infected file on disk, the Trojan that resides in memory is essentially invisible to the system.

All of this supports a report released by NSS Labs last week that found many anti-virus applications fail to find malware that attempts to infect systems through multiple entry points, such as e-mail or USB drives. The independent testing company evaluated the effectiveness of 10 popular antivirus applications against multi-vector attacks (malware delivered from the web, e-mail, network file sharing and USB flash drives), memory-only attacks, and anti-evasion techniques.

Also see: Experts only: Time to ditch the antivirus?

The report, titled Socially-Engineered Malware Via Multiple Attack Vectors, found that anti-virus applications that find malware at one point-of-entry may not detect it in another. A web download, for example, could be missed if downloaded from a USB drive or network file server.

The report found that antivirus products miss between 10 per cent and 60 per cent of the evasions most often used by attackers. Furthermore, Less than a third of the tested vendors had protection for memory-only malware, leaving a significant evasion gap in their products.

Typically, according to the report, these evasion techniques include placing a wrapper, or a disguise, that are applied to exploits and malware in an attempt to thwart detection. "An exploit that is detected by a security product can be modified by an evasion technique to still get through to the target -- if the intermediary security product does not have the appropriate anti-evasion capability," the report stated.

None of that surprises Moyer. "It's fairly trivial to customize an exploit to bypass 70 per cent of the time. I do it all of the time on engagements," Moyer says.

How important is it for anti-malware software to be able to stop each and every attack? Stewart has some sobering news about what the attackers do once they gain any kind of foothold. "They'll conduct a lot of network probing. They'll look for vulnerable network servers, web servers, SQL servers, and other areas where they can gain another foothold: weak passwords. File shares, and they'll go from there. Moving point to point and extract whatever data they can," he says.

George V. Hulme writes about security and technology from his home in Minneapolis. You can also find him tweeting about these topics @georgevhulme on Twitter.

Read more about data protection in CSOonline's Data Protection section.

Join the CSO newsletter!

Error: Please check your email address.

Tags stealth malwaresymantecsecuritydata protectionmalwareTrojan horse

More about FacebookSymantec

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by George V. Hulme

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts