April 21, 2015 By Etay Maor 2 min read

One of the interesting topics IBM teams analyze is the ways in which malware authors constantly innovate their cyberfraud techniques when it comes to evading detection either by endpoint solutions, such as antivirus tools, or research and enterprise security systems, such as sandboxes and reverse engineering techniques.

Attacks involving Trojans are always interesting since they differ from most other threats in that they try to stay covert. While attacks such as phishing, distributed denial-of-service, defacement and ransomware attacks are visible and do not try to hide the actual attack from the victim, Trojan horses are unique because their success in harvesting credentials and survivability rely on how well they evade researchers’ analysis, detect devices and persist on an infected system after they are detected.

1. Evading Security Researchers

Once a malware campaign starts, it’s only a matter of time before the new variant is detected and analyzed. However, malware authors benefit from prolonging the time it takes researchers to analyze the variant. It will take researchers longer to analyze the malware if there are barriers such as file encryption in place and security awareness mechanisms such as virtual machine-aware malware that will not install on virtual devices. This leads to a slower distribution of countermeasures. It is also worth noting that some types of malware use specific tricks to overcome detection by sandboxes, such as specific time delays and targeting micro-enabled Office applications.

2. Evading Endpoint Protection Systems

The most widespread and obvious example is that of antivirus solutions. Many Trojan horses and malware droppers use different tools and tricks to avoid antivirus detection. These range from encrypting software and services that help protect the malware from many antivirus solutions to cases in which the malware installs a lightweight Linux OS, reboots the device with the Linux kernel, deletes security software (something it cannot do in Windows mode since it would need administrative privileges) and rebooting back in Windows, now with no security software to get in the way.

3. Persistence After Cyberfraud Detection

Ultimately, the malware may hopefully get detected, but not all hope is lost when it comes to Trojan horses. There are several techniques malware authors use to remain on the infected system even after the Trojan is detected. These can include rootkits and infecting the system master boot record, or sunning a watchdog process that constantly monitors the malware files. If the malware is removed, the watchdog process will identify the change and initiate a new download of the malware.

Evading detection and analysis is just one area in which cybercriminals are investing time and effort. Join my “Major Cyberfraud Innovations of the Last Twelve Months” session at the RSA Conference 2015 to learn more about what malware, cybercriminals and fraudsters have been up to and hear about the latest case studies and research conducted by IBM Security’s innovation, security and threat teams.

More from Fraud Protection

Virtual credit card fraud: An old scam reinvented

3 min read - In today's rapidly evolving financial landscape, as banks continue to broaden their range of services and embrace innovative technologies, they find themselves at the forefront of a dual-edged sword. While these advancements promise greater convenience and accessibility for customers, they also inadvertently expose the financial industry to an ever-shifting spectrum of emerging fraud trends. This delicate balance between new offerings and security controls is a key part of the modern banking challenges. In this blog, we explore such an example.…

Remote access detection in 2023: Unmasking invisible fraud

3 min read - In the ever-evolving fraud landscape, fraudsters have shifted their tactics from using third-party devices to on-device fraud. Now, users face the rising threat of fraud involving remote access tools (RATs), while banks and fraud detection vendors struggle with new challenges in detecting this invisible threat. Let’s examine the modus operandi of fraudsters, prevalence rates across different regions, classic detection methods and Trusteer’s innovative approach to RAT detection through behavioral analysis. A rising threat As Fraud detection methods become more and…

Gozi strikes again, targeting banks, cryptocurrency and more

3 min read - In the world of cybercrime, malware plays a prominent role. One such malware, Gozi, emerged in 2006 as Gozi CRM, also known as CRM or Papras. Initially offered as a crime-as-a-service (CaaS) platform called 76Service, Gozi quickly gained notoriety for its advanced capabilities. Over time, Gozi underwent a significant transformation and became associated with other malware strains, such as Ursnif (Snifula) and Vawtrak/Neverquest. Now, in a recent campaign, Gozi has set its sights on banks, financial services and cryptocurrency platforms,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today