Blog | G5 Cyber Security

CSE Malware ZLab Double Process Hollowing -The stealth process injection of the new Ursnif malware

A new variant of the infamous Ursnif malware spread in the wild and adopts a new advanced evasion technique dubbed Double Process Hollowing. The command and control of this new malware, oretola[.]at has been sinkholed by authorities, so it is difficult to reconstruct the entire behavior and the real purpose of this malware. The malware uses almost exclusively the Native API of Windows with also its undocumented functions. The use of them causes a more difficult monitoring by antiviruses.”]

Source: https://securityaffairs.co/wordpress/67636/cyber-crime/process-hollowing-ursnif-malware.html

Exit mobile version