HomeSecurityHow malware tricks users and antivirus programs

How malware tricks users and antivirus programs

One of the main methods used by hackers to infect devices is to trick people into downloading and running malicious files. To achieve this, malware creators use various tricks .

See also: Fake Windows 11 upgrade installs malware

malware

Some of these tricks include disguising malware executables as legitimate applications, signing them with valid certificates, or compromising trusted sites to use as distribution points.

According to VirusTotal, some of these tricks occur on a much larger scale than we initially thought.

The platform has compiled a report presenting statistics from January 2021 to July 2022, based on the submission of two million files daily, which illustrates the trends in the distribution of malicious software.

The distribution of malicious software through legitimate, popular websites allows threat actors to evade IP‑based blocks, enjoy high availability, and provide a higher level of trust.

VirusTotal detected 2.5 million suspicious files downloaded from 101 domains belonging to Alexa.

The most notable case of abuse is Discord, which has become a hotbed for malware distribution, with hosting and cloud service providers Squarespace and Amazon also recording large numbers.

See also: Serpent malware abuses Chocolatey Windows

Signing malware samples with valid certificates stolen from companies is a reliable way to avoid AV detection and security warnings on the host computer.

antivirus

The most common certificate authorities used to sign malicious samples submitted to VirusTotal include Sectigo, DigiCert, USERTrust , and Sage South Africa.

The masquerading of a malicious executable as a legitimate, popular application has seen an upward trend in 2022.

Victims download these files thinking they are getting the applications they need, but when they run the installers, they infect their systems with malware.

The applications that are most impersonated are Skype, Adobe Acrobat, VLC, and 7zip.

The popular Windows optimization program CCleaner , which we saw in a recent SEO infection campaign, is among the prominent choices of hackers and has an extremely high infection ratio for its distribution volume.

Finally, there is the trick of hiding malicious software inside legitimate application installers and executing the infection process in the background while the real applications run in the foreground.

See also: MySQL servers hit by Gh0stCringe malware

How will you protect yourself?

When you want to download software, use the built-in app store of your operating system or the official download page of the application. Also, watch out for promoted ads in search results that may be ranked higher, as they can easily be forged to look like legitimate websites.

After downloading an installer, always run an AV scan on the file before executing it, to ensure it does not contain hidden malicious software.

Finally, avoid using torrent for cracks or keygens for copyrighted software, as they usually lead to malware infection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS