- Sep 2, 2021
- 2,595
Is running a stealer malware in a fresh VM safe?
If you were to run a stealer, and it doesnt try to escape the VM, would it be safe? Is there anything to steal? Could the system info of the VM being stolen be of harm?
This is saying no extra passwords, nothing logged in, etc.
I've been working with virtual machines for a very long time, both personally and now in video, and I've learned a lot about malware evasion.
Not all virtualization software works the same way, and many have significant vulnerabilities when it comes to malware.
I highly recommend VMware and configuring your VM in Bridge mode rather than NAT. In NAT, your host PC acts as a gateway and is vulnerable to malware (I got infected by Virut that way a long time ago...).
In Bridge mode, your VM connects directly to your internet router. You'll need a VPN to hide your IP since you'll be connecting to C&C servers, which are often controlled by hackers. If you have a NAS, disconnect it, as several Ransomware strains also encrypt network shares!!