Security researchers have revealed the latest tricks used by hackers behind the GuLoader malware to make analysis more difficult.

“While the core functionality of GuLoader has not changed drastically in recent years, these constant updates to obfuscation techniques make analyzing GuLoader a time-consuming and resource-intensive process,” said Elastic Security Labs researcher Daniel Stepanic.
GuLoader malware was first detected in late 2019, and is an advanced shellcode-based malware downloader, which is used to distribute various malicious payloads, while incorporating a series of sophisticated anti-analysis techniques to evade traditional security.
See also: Trickbot malware: Russian developer pleads guilty
GuLoader is typically distributed through campaigns phishing. Attackers send malicious messages to victims and convince them to download and install the malware by opening ZIP files or links containing a Visual Basic Script (VBScript) file.
Israeli cybersecurity firm Check Point recently revealed that “the GuLoader malware is now being sold under a new name on the same platform as Remcos and is being tacitly promoted as a crypter that makes its payload undetectable by antiviruses.”
One of the recent changes in the malware is the improvement of an anti-analysis technique first revealed by CrowdStrike in December 2022. This is based on the malware's Vectored Exception Handling (VEH) capability
See also: New proxy trojan malware targets Mac users
This mechanism has also been reported by McAfee Labs and Check Point, with the former stating that “GuLoader uses VEH primarily to cover the execution flow and slow down analysis.”
The method “consists of interrupting the normal flow of code execution by deliberately throwing a large number of exceptions and handling them in a vector exception handler that transfers control to a dynamically calculated address,” Check Point said.

Cybercriminals place great emphasis on avoiding detection and analysis of their malware. One of the main benefits of using such techniques is avoiding tools that analyze malicious activity. These techniques can obfuscate the malware code or encrypt it, making it more difficult to detect. This allows malware authors to continue attacking systems for a long time.
See also: FjordPhantom: Android malware uses virtualization to evade detection
Another benefit is the difficulty in retrieving information from malware. Anti-analytics techniques can limit researchers' ability to analyze malware code and derive information about how it works, potential vulnerabilities, or sources of attacks. This makes it more difficult to combat malware and develop effective methods of protecting against it.
Finally, the use of anti-analysis techniques can allow malware authors to “stay ahead” of the actions of authorities and researchers. These techniques can delay analysis and response to malware, allowing authors to attack new targets and cause more damage.
Source: thehackernews.com
