'Waterbear' Employs API Hooking to Hide Malicious Behavior

Discussion in 'malware problems & news' started by mood, Dec 13, 2019.

  1. mood

    mood Updates Team

    Oct 27, 2012
    'Waterbear' Employs API Hooking to Hide Malicious Behavior
    December 13, 2019
    Trend Micro: Waterbear is Back, Uses API Hooking to Evade Security Product Detection
  2. Rasheed187

    Rasheed187 Registered Member

    Jul 10, 2004
    The Netherlands
    But isn't it true that in order to use API hooking, you first need to perform code injection? So if security tools can block this, they can also stop the API hooking part. Or better yet, Windows should it make it harder to perform API hooking, only "trusted" security tools should be able to do this. Similar to how they protected the kernel with PatchGuard.
