Malvertising attacks are distributing .NET malware loaders — .NET Virtualization Thrives

Discussion in 'malware problems & news' started by guest, Feb 2, 2023.

  1. guest

    guest Guest

    By Jeff Burt @jburttech - February 2, 2023
    SentinelLabs: MalVirt | .NET Virtualization Thrives in Malvertising Attacks
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Well, I'm sure I didn't understand everything, but it seems like this fairly new .Net virtualization technique is mostly being used to bypass AV detection. But I'm guessing it will still trigger quite a lot of stuff that should be spotted by behavior blockers, for example if they load system processes and when they try to load the legitimate Process Explorer driver.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.