When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Stealth virus is stealthiest of all

There's a new mass mailing virus in town, and it's built to make life for AV researchers even more difficult. Atak uses a variety of tactics in its attempts to escape antivirus analysis. Its main trick is to check to see if it's being run in a debugging environment. If so, it exits to avoid detection. The ploy prevents casual perusal of the code by researchers and (potentially) rival virus writers.

A possible bug, related to the way Atak checks its activation date, prevents it from being run in a "sandbox". A sandbox is a virtual environment commonly used by AV researchers to look at the behaviour of malware in a safe environment. "I haven't seen such ruses used in a mass mailer in a long time. This piece of code is so sloppy, it's devious," said Mircea Ciubotariu, a researcher at Romanian AV firm BitDefender.

View: The full story

News source: The Reg

Report a problem with article
Next Article

Intel made way too many Prescotts in Q2

Previous Article

Digital Entertainment Dominates Macworld

Join the conversation!

Login or Sign Up to read and post a comment.

-1 Comments - Add comment