Antivirus

This previously unknown malware has some crafty tricks for avoiding antivirus

Cybersecurity researchers from Trend Micro have uncovered a brand new piece of malware that uses an unusual method of hiding from antivirus programs. The malware is called UNAPIMON, and is apparently being used by Winnti, an established Chinese state-sponsored threat actor that was behind some of the most devastating attacks against governments, hardware and software

Cybersecurity researchers from Trend Micro have uncovered a brand new piece of malware that uses an unusual method of hiding from antivirus programs.

The malware is called UNAPIMON, and is apparently being used by Winnti, an established Chinese state-sponsored threat actor that was behind some of the most devastating attacks against governments, hardware and software vendors, think tanks, and more.

According to Trend Micro, many malware variants are using a method known as API hooking to eavesdrop on calls, grab sensitive data, and tweak different software. Therefore, many security tools also use API hooking to track the malware.

Simplicity and originality

“With UNAPIMON, things are different. It uses Microsoft Detours for hooking the CreateProcessW API function, which allows it to unhook critical API functions in child processes. As a result, it successfully evades antivirus detection. 

A unique and notable feature of this malware is its simplicity and originality,” Trend Micro said in its report. “Its use of existing technologies, such as Microsoft Detours, shows that any simple and off-the-shelf library can be used maliciously if used creatively. This also displayed the coding prowess and creativity of the malware writer.”

“In typical scenarios, it is the malware that does the hooking. However, it is the opposite in this case.”

Using Microsoft Detours in this regard has other benefits, too, the researchers expla

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

The best Android antivirus in 2025: Save 50% on Avast Mobile Security

The best Android antivirus in 2025. As of March 10, Avast Mobile Security is offering half off its paid plans for the first year…

The best Android antivirus in 2025. As of March 10, Avast Mobile Security is offering half off its paid plans for the first year…
Read More

Continue Reading
Antivirus

McAfee Total Protection review: Top security undermined by a major feature

At a GlanceExpert’s Rating Pros Solid antivirus protection Broad protection against online threats Cons Can heavily impact performance on some PCs User interface is a little scattered Password manager is difficult to use Our Verdict McAfee Total Protection’s strengths lie in its defenses against malware, network…

At a GlanceExpert’s Rating

Pros

Solid antivirus protection

Broad protection against online threats

Cons

Can heavily impact performance on some PCs

User interface is a little scattered

Password manager is difficult to use

Our Verdict
McAfee Total Protection’s strengths lie in its defenses against malware, network…
Read More

Continue Reading
Antivirus

Antivirus software company ordered to pay customer $16.5M: How to file a claim

Millions of American consumers who bought antivirus software from Avast may be eligible to receive a portion of a $16.5 million settlement, the Federal Trade Commission (FTC) announced Monday…

Millions of American consumers who bought antivirus software from Avast may be eligible to receive a portion of a $16.5 million settlement, the Federal Trade Commission (FTC) announced Monday…
Read More

Continue Reading
Antivirus

Chinese hackers abuse Microsoft APP-v tool to evade antivirus

The Chinese APT hacking group “Mustang Panda” has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to evade detection by antivirus software. …

The Chinese APT hacking group “Mustang Panda” has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to evade detection by antivirus software. …
Read More

Continue Reading