Hackers are exploiting legitimate and commercially available packer software, such as BoxedApp, to evade detection and distribute malware, including remote access trojans and information-stealing malware.

According to a report by Check Point, most malicious samples targeted financial institutions and government agencies.
The volume of samples packaged with BoxedApp and submitted to the malware scanning platform VirusTotal increased sharply around May 2023, with artifact submissions primarily originating from Turkey, the US, Germany, France, and Russia.
See also: Malware can steal data collected by Windows Recall
Researchers observed that the packer software was mainly used to distribute the following malware: Agent Tesla, AsyncRAT, LockBit, LodaRAT, NanoCore, Neshta, NjRAT, Quasar RAT, Ramnit, RedLine, Remcos, RevengeRAT, XWorm, and ZXShell.
Packers are self-extracting archives that are often used to compress software to make it smaller. But in recent years, they have been increasingly used by cybercriminalsto add an extra layer of obfuscation and evade analysis.
The increase in the abuse of packer software, such as BoxedApp Packer and BxILMerge, is due to a number of advantages that make them an attractive option for distributing malware without being detected by security.
BoxedApp Packer can be used to package both native and .NET PE, while BxILMerge – similar to ILMerge – is intended exclusively for packaging .NET applications.
That said, BoxedApp-packed applications, including non-malicious ones, suffer from a high false positive (FP) detection rate when scanned by anti-malware engines.
See also: Hackers target Russia with Decoy Dog malware
“Packing malicious payloads allowed attackers to reduce the detection of known threats, make them more difficult to analyze, and utilize advanced features of the BoxedApp SDK (e.g., Virtual Storage) without having to develop them from scratch,” the company said.
Malware protection
Using reliable and up-to-date antivirus is essential for protection against malware. Antivirus programs can detect and remove malicious software, as well as provide continuous real-time protection.
Regularly updating your operating system and software is also critical. Updates include security that close gaps that attackers could exploit.

Next is using strong and unique passwords for each account. Passwords should include a combination of letters, numbers, and special characters to make them harder to crack.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Fake browser updates distribute BitRAT and Lumma Stealer malware
Enabling multi-factor authentication (MFA) adds an extra layer of security. Even if someone gets your password, they'll still need the second factor to gain access.
It is also very important to avoid clicking on suspicious links and attachments in emails and messages. Attackers often use phishing emails to trick users into installing malware on their computers.
Source: thehackernews.com
