A new malware strain, dubbed Stealth Falcon, takes a novel approach to avoiding detection on the Internet. It uses the BITS protocol on Windows machines, which is usually enabled and can bypass firewalls . The protocol is ideal for detecting and stopping exfiltrating data, demonstrating the need for Data Leakage Prevention (DLP).

What is the BITS protocol?
The Stealth Falcon malware is designed to be invisible in a number of ways. However, its unique feature is its use of the BITS protocol for data exfiltration.
The Background Intelligent Transfer Service (BITS) protocol was designed by Microsoft to allow large file uploads and downloads without affecting the user's network connection speed. This protocol is commonly used to download software updates, so many companies allow it to pass through their firewalls. The terms “background” and “intelligent” in the BITS protocol name refer to the fact that it tries to minimize its impact on the user's experience on the computer. BITS recognizes when a computer has unused network bandwidth and uses that bandwidth for the download. As a result, the BITS protocol is very unobtrusive, making it difficult to detect when it is running on a network.

Stealth Falcon Malware
The BITS protocol's stealthiness makes it ideal for malware trying to keep command and control (C2) under the radar. Additionally, because it won't get caught in the firewall and is used by many different software vendors for updates, most companies are unlikely to be suspicious of downloading and uploading data in unusual segments.
Recently, the Stealth Falcon malware was discovered to use BITS for its data removal and C2 communications. Stealth Falcon takes care to hide its communications by creating an encrypted copy of the file before transmission and deleting the logs and encrypted copies of the files once the communication is complete. Since BITS uploads/downloads have the ability to persist across reboots and user logouts, the malware’s C2 protocol is both invisible and resilient.
