HomeSecurityMylobot: the malware you wouldn't want on your computer...

Mylobot: the malware you wouldn't want on your computer

Mylobot: In 2017, security researchers discovered about 23,000 new malware samples every day, or 795 per hour.
If that number seems high to you, consider that the majority of these samples were variations of a few different malware. They had slightly different code, so as to create a “new” signature.Mylobot
From time to time, however, completely new malware appears on the scene. Mylobot is one such example: it’s new, highly sophisticated, and very powerful.

What is Mylobot?

Mylobot is a botnet-type malware. The new malware was first spotted by Tom Nipravsky, a security researcher at Deep Instinct. The researcher said that “the combination and complexity of the techniques it contains have never been known before.”
Indeed, the new malware has very sophisticated infection and entrapment techniques in one package. Take a look:
Anti-virtual machine (VM) techniques: The malware checks its local environment to discover virtual machines if it fails to run.
Anti-sandbox techniques: Very similar to anti-VM techniques.
Anti-debugging techniques: For security researchers trying to see what the code of the new malware contains.
Use of encryption on important parts of the code: to further protect the malware code.
Code injection techniques: Mylobot runs custom code that attacks systems by adding its code to system processes.
Stealth techniques: The attacker creates a new process in a suspended state, and then replaces it with the one he wants to hide.
Reflective EXE: EXE files run from memory, not from disk.
Delay mechanism: The malware remains dormant for 14 days before it starts connecting to command and control servers.
Sandboxing, anti-debugging, and anti-VM techniques that attempt to stop all malware do not seem to be able to stop Mylobot. Reflective exe running from the operating system's memory makes Mylobot almost invisible, as there is no direct activity on the disk that any antivirus or antimalware can detect.

According to Nipravsky from Threatpost:

The structure of the code itself is very complex (it is a multi-threaded malware where each thread is responsible for implementing different features).

And:

The malware contains three layers of files, nested within each other, where each layer is responsible for executing the next. The last layer uses the Reflective EXE technique.

By staying away from analysis and detection techniques, Mylobot can wait up to 14 days before attempting to communicate with command and control servers. When Mylobot connects, the botnet disables Windows Defender, Windows Update, and several Windows Firewall ports.
One of the most interesting and rare features of the Mylobot malware is its search and destroy feature.
Unlike other malware, when Mylobot is installed, it eliminates any other malware (if any) on the target system. Mylobot scans the system for malware and terminates any process it finds.
Nipravsky believes that this feature was added to stop ransomware-as-a-service operations and other pay-to-play malware variants that anyone can rent online.

Attackers compete with each other to have as many zombie computers as possible to increase the value of the bot they have available for rent to other attackers.

What does Mylobot do, exactly?

Mylobot's main function is to hand over control of the system to the attacker. From there, the attacker can access online credentials, system files, and more.
Mylobot has a lot of connections to other botnets, such as DorkBot, Ramdo, and the infamous Locky network. If Mylobot acts as a conduit for all other botnets, the victim of this malware will not fare well.

How can you stay safe from Mylobot?

The bad news for now: Mylobot is believed to have been infecting systems for over two years. The command-and-control servers it uses were first operational in November 2015.
So Mylobot appears to have eluded many researchers and security firms for quite some time before being discovered by Deep Instinct.
Unfortunately, today’s antivirus tools cannot detect Mylobot – at least not yet.
But now that a sample of Mylobot is available, security firms will be able to have its digital signature to use in future detection.
_____________________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS