Enter your email address below and subscribe to our newsletter

The new stealth threats

Share your love

PandaLabs has revealed that 78% of new malware uses some kind of file packing to evade detection. A packer is a program used
to reduce the size of an executable file, generally through compression. However, these programs can also be used to protect
copies of malicious code installed on computers or to make it more difficult for antivirus solutions to detect them when they are
distributed.


In essence it is a stealth technique,” explains Jeremy Matthews, CE of Panda Software South Africa . “The increasing use of these programs highlights how keen Internet criminals are for their creations to go undetected. There are more than 500 other packers used by cyber-crooks.

These tools allow the combination of several malicious files in a single packer, hindering detection.

The problem is when to detect this malicious code. Most are packed with legal programs, and it is not possible to distinguish between goodware and malware just by the packer. What is the solution? In the case of emails, there has to be a system to detect them before they reach the computer. Security solutions have to be able to detect packed malware before users execute it,says Matthews.

Some of the most prominent malicious codes in recent months used packers, such as the Conycspa.AJ Trojan, which downloaded several other malicious codes, the Clagge.G Trojan and the Rinbot.Q worm, which spread by exploiting several Windows vulnerabilities.

Another important and relatively unknown danger comes in the form of binders or joiners. These are programs designed to join two or more files together. These tools are used by hackers to hide their malicious creations within an apparently inoffensive file.

All users that want to know whether their computers have been attacked by this or other malicious code can use TotalScan (which now detects one million threats) or NanoScan beta, the free online
solutions available at www.infectedornot.com.