Chinese computer pirates abuse the Microsoft tool to overcome antivirus and wreak havoc




  • Trend Micro has seen the land pretending to antivirus in a new attack
  • Malware implementation checks to see if the antivirus eset is installed
  • Malware kidnappings Legitimate processes to inject malicious code

A group of Chinese piracy tracked such as Earth Preta and Mustang Panda has been seen using the Microsoft applications virtualization injector to avoid antivirus software injecting malicious code in legitimate processes.

A new investigation of the Trend Micro threat hunting equipment revealed how the group has also been using the configuration factory, a third -party Windows installers builder, to leave and malicious executive useful loads.

Leave a Comment

Your email address will not be published. Required fields are marked *