Security News Malware Author Inflates Backdoor Trojan With Junk Data Hoping to Avoid Detectio

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
A malware coder is injecting megabytes of junk data inside his malicious payloads, hoping to avoid detection by some antivirus solutions or delay investigations of infosec professionals.
Known only as "123", this malware coder has been active since 2015, when he was first spotted deploying the XXMM malware. His activity falls in the category of targeted attacks, this crook focusing on infecting computers at Japanese companies for the purpose of exfiltrating sensitive data.
123 malware author behind three malware families

According to reports, this threat actor is behind at least three malware families, named XXMM, ShadowWali, and Wali, respectively.
Security firms noted 123's initial attacks with the XXMM malware in 2015, but they deemed it an usophisticated, albeit very effective, backdoor.
The interest in 123's activities piqued again over the past month after they unearthed two new malware families created by the same coder.

Read More. Malware Author Inflates Backdoor Trojan With Junk Data Hoping to Avoid Detection
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Really raw and not sophisticated technique, but it is necessary not to underestimate any malware attack.
 
  • Like
Reactions: frogboy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top