Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le décembre 11, 2019, 15:00:08

Titre: [Trend]Waterbear is Back, Uses API Hooking to Evade Security Product Detection
Posté par: igor51 le décembre 11, 2019, 15:00:08
Waterbear is Back, Uses API Hooking to Evade Security Product Detection

In one of its recent campaigns, we’ve discovered a piece of Waterbear payload with a brand-new purpose: hiding its network behaviors from a specific security product by API hooking techniques. In our analysis, we have discovered that the security vendor is APAC-based, which is consistent with BlackTech’s targeted countries. 


The post Waterbear is Back, Uses API Hooking to Evade Security Product Detection appeared first on .


Source: Waterbear is Back, Uses API Hooking to Evade Security Product Detection (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/LF5q_2AY-vQ/)