Blog | G5 Cyber Security

TrickBot now crashes researchers’ browsers to block malware analysis

IBM Trusteer researchers have analyzed recent samples of TrickBot malware. The notorious banking trojan has been linked to the Diavol ransomware group, the Conti ransomware gang, and even the re-emergence of Emotet. TrickBot’s developers use a range of obfuscation and base64 encoding layers for the scripts, including minify, string extraction and replacement, number base and representing, dead code injection, and monkey patching. It also uses an anti-debugging script in the JS code, which helps it anticipate when it is being analyzed and triggers a memory overload that crashes the page.”]

Source: https://www.bleepingcomputer.com/news/security/trickbot-now-crashes-researchers-browsers-to-block-malware-analysis/

Exit mobile version