HomeSecurityMalware uses Windows to infect computers

Malware uses Windows to infect computers

Windows

Cybercriminals have developed a new tool to help them distribute malware to computers by abusing legitimate Windows and constantly improving their code. The recent malware downloader was dubbed “f0xy” by researchers at Websense when they analyzed it to see its capabilities.

According to their analysis, the threat's developers are constantly working on it, in order to achieve a version that is compatible with the largest number of operating systems and that can run unnoticed for longer periods of time.

Researchers found that f0xy relies on a dynamic list of C&C servers to push malicious files. Another strategy adopted by the developers to avoid detection is to use Microsoft's transfer service to download data to the computer.

Some of the samples identified by Websense date back to January 2015 and can only run on Windows Vista and later. Newer versions have been developed, however, including support for Windows XP.

The malware downloaded from f0xy does not steal sensitive information such as passwords or financial details. It appears that its administrators are using it to make money, as Websense observed, by installing a crypto-currency miner on the affected system.

At the time of testing, only five of the 57 anti-virus available on VirusTotal were able to detect the malware. However, subsequent scans conducted three days ago showed improved detection, with 10 software able to detect the malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS