Tuesday, July 23, 2024

Early Bird – A Malware Code Injection Technique to Evade the Detection by Anti-Malware

Advanced Malware threats nowadays using powerful Code Injection Technique called  “Early Bird” that helps to evade the detection by Anti-Malware software.

Code injection technique allows malware inject the malicious code into a legitimate process and run before an entry point of the process in Main threat.

This New technique abuse the anti-malware product to evade the detection since the malicious injection process started earlier before an Anti-Malware start its scanning process.

Since the Malicious code has been injected before the entry point of the legitimate process, anti Malware scan only perform the legitimated process hence obfuscates the malicious code execution.

Various new Malware is using this technique such as DorkBot to evade the detection and compromise the targeted computers.

How does “Early Bird” Code Injection Technique Works

Early Bird Code injection flaw starts with creating a suspended process (a new process that executes and continue within the running process) and this suspended process(svchost.exe) most likely to be legitimate windows process.

Once the suspended process(svchost.exe) will be created then malware allocate a memory and write malicious code to that process.

After the required memory allocation, it Writes the Malicious code into the allocated memory space its also called hollow process infection.

Later it Queues an asynchronous procedure call (APC) to execute the code on the main thread and resuming the thread for the execution and the start address pointed to the entry point of Malicious code.

According to Microsoft, When a user-mode APC is queued, the thread to which it is queued is not directed to call the APC function unless it is in an alertable state” so APC will be in an alertable state in order to execute the APC.

According to cyberbit Research, “the thread has not even started its execution since the process was created in a suspended state. How does the malware “know” that this thread will be alertable at some point? Does this method work exclusively on svchost.exe or will it always work when a process is created in a suspended state?”

In this case, Malware can able to abuse the other process as well and researchers analyse the process that reveals when resuming the main threat and it loads the malicious code in a very early stage of thread initialization, before many security products place their hooks – which allows the malware to perform its malicious actions without being detected.

Early Bird code injection video


Latest articles

Beware Of Dating Apps Exposing Your Personal And Location Details To Cyber Criminals

Threat actors often attack dating apps to steal personal data, including sensitive data and...

Hackers Abusing Google Cloud For Phishing

Threat actors often attack cloud services for several illicit purposes. Google Cloud is targeted...

Two Russian Nationals Charged for Cyber Attacks against U.S. Critical Infrastructure

The United States has designated Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, two members...

Threat Actors Taking Advantage of CrowdStrike BSOD Bug to Deliver Malware

Threat actors have been found exploiting a recently discovered bug in CrowdStrike's software that...

NCA Shut’s Down the Most Popular “digitalstress” DDoS-for-hire Service

The National Crime Agency (NCA) has successfully infiltrated and dismantled one of the most...

Play Ransomware’s Linux Variant Attacking VMware ESXi Servers

A new Linux variant of Play ransomware targets VMware ESXi environments, which encrypts virtual...

SonicOS IPSec VPN Vulnerability Let Attackers Cause Dos Condition

SonicWall has disclosed a critical heap-based buffer overflow vulnerability in its SonicOS IPSec VPN....
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles