Tech

Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc

Share
Share


  • Trend Micro has spotted Earth Preta dodging antivirus in new attack
  • The malware deployment checks to see if ESET antivirus is installed
  • Malware hijacks legitimate processes to inject malicious code

A Chinese hacking group tracked as Earth Preta and Mustang Panda has been spotted using the Microsoft Application Virtualization Injector to dodge antivirus software by injecting malicious code into legitimate processes.

New research from Trend Micro’s Threat Hunting team revealed how the group has also been using Setup Factory, a third-party Windows installer builder, to drop and executive malicious payloads.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles