article thumbnail

Chinese Antivirus Firm Was Part of APT41 ‘Supply Chain’ Attack

Krebs on Security

One of the alleged hackers was first profiled here in 2012 as the owner of a Chinese antivirus firm. APT41’s activities span from the mid-2000s to the present day. When I first scanned Anvisoft at Virustotal.com back in 2012, none of the antivirus products detected it as suspicious or malicious. Image: FBI.

Antivirus 363
article thumbnail

Hiding Malware in ML Models

Schneier on Security

In this paper, we present a method that delivers malware covertly and detection-evadingly through neural network models. Meanwhile, since the structure of the neural network models remains unchanged, they can pass the security scan of antivirus engines.

Malware 363
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Experts warn of flaws in popular Antivirus solutions

Security Affairs

Researchers disclosed details of security flaws in popular antivirus software that could allow threat actors to increase privileges. Security researchers from CyberArk Labs disclosed details of security vulnerabilities found in popular antivirus software that could be exploited by attackers to elevate their privileges on the target system.

Antivirus 136
article thumbnail

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

Security Affairs

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute backdoors and cryptocurrency miners. Avast researchers discovered and analyzed a malware campaign that exploited the update mechanism of the eScan antivirus to distribute backdoors and crypto miners.

Antivirus 131
article thumbnail

CVE-2024-5102: Avast Antivirus Flaw Could Allow Hackers to Delete Files and Run Code as SYSTEM

Penetration Testing

A high-severity vulnerability (CVE-2024-5102) has been discovered in Avast Antivirus for Windows, potentially allowing attackers to gain elevated privileges and wreak havoc on users’ systems.

Antivirus 104
article thumbnail

Data From The Qakbot Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI

Troy Hunt

Pwned Passwords is presently requested 5 and a half billion times each month to help organisations prevent people from using known compromised passwords. Further, the passwords from the malware will shortly be searchable in the Pwned Passwords service which can either be checked online or via the API.

Malware 362
article thumbnail

Hackers Abuse Google Ads to Send Antivirus Avoiding Malware

Heimadal Security

The downloads presented by the fraudulent sites try spoofing Microsoft, Acer, DigiCert, Sectigo, and AVG […] The post Hackers Abuse Google Ads to Send Antivirus Avoiding Malware appeared first on Heimdal Security Blog. MalVirt loaders are promoted by threat actors in advertising that appears to be for the Blender 3D program.