
Windows Malware Corrupts PE Headers While Dropping Files to Evade On-Access Scanners
Researchers have uncovered a custom Windows backdoor that uses several low-noise techniques to avoid detection, including corrupting executable headers while writing dropped files to disk. The malware was found on a single 64-bit Windows 7 corporate workstation during a hunt for suspicious WMI persistence. The backdoor disguised itself as Realtek audio software and used a […]
The post Windows Malware Corrupts PE Headers While Dropping Files to Evade On-Access Scanners appeared first on Cyber Security News.