Python and Malware: Developing Stealth and Evasive Malware Without Obfuscation

05/02/2021
by   Vasilios Koutsokostas, et al.
0

With the continuous rise of malicious campaigns and the exploitation of new attack vectors, it is necessary to assess the efficacy of the defensive mechanisms used to detect them. To this end, the contribution of our work is twofold. First, it introduces a new method for obfuscating malicious code to bypass all static checks of multi-engine scanners, such as VirusTotal. Interestingly, our approach to generating the malicious executables is not based on introducing a new packer but on the augmentation of the capabilities of an existing and widely used tool for packaging Python, PyInstaller but can be used for all similar packaging tools. As we prove, the problem is deeper and inherent in almost all antivirus engines and not PyInstaller specific. Second, our work exposes significant issues of well-known sandboxes that allow malware to evade their checks. As a result, we show that stealth and evasive malware can be efficiently developed, bypassing with ease state of the art malware detection tools without raising any alert.

READ FULL TEXT
research
06/14/2019

Antiforensic techniques deployed by custom developed malware in evading anti-virus detection

Both malware and antivirus detection tools advance in their capabilities...
research
04/23/2019

PowerDrive: Accurate De-Obfuscation and Analysis of PowerShell Malware

PowerShell is nowadays a widely-used technology to administrate and mana...
research
05/28/2019

Hydras and IPFS: A Decentralised Playground for Malware

Modern malware can take various forms, and has reached a very high level...
research
09/19/2020

Optimizing Away JavaScript Obfuscation

JavaScript is a popular attack vector for releasing malicious payloads o...
research
06/23/2023

Full Transparency in DBI frameworks

Following the increasing trends of malicious applications or cyber threa...
research
03/02/2019

The Historical Perspective of Botnet tools

Bot as it is popularly called is an inherent attributes of botnet tool. ...

Please sign up or login with your details

Forgot password? Click here to reset