Sunday, February 23, 2025
HomeNewsChinese hackers abuse Microsoft tool to get past antivirus and cause havoc

Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc


  • Trend Micro has spotted Earth Preta dodging antivirus in new attack
  • The malware deployment checks to see if ESET antivirus is installed
  • Malware hijacks legitimate processes to inject malicious code

A Chinese hacking group tracked as Earth Preta and Mustang Panda has been spotted using the Microsoft Application Virtualization Injector to dodge antivirus software by injecting malicious code into legitimate processes.

New research from Trend Micro’s Threat Hunting team revealed how the group has also been using Setup Factory, a third-party Windows installer builder, to drop and executive malicious payloads.

Source

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular