Smoke Loader Backdoor Gets Anti-Analysis Improvements

The Smoke Loader installer, the security researchers explain, spawns an EnumTools thread to detect and evade analysis tools, and uses an API to enumerate running analysis utilities. The malware checks for twelve analysis processes via a hash-based method, and terminates itself if one is found running.

Read full news article on SecurityWeek

 


Date:

Categorie(s):