Symantec, a division of Broadcom Software, has identified a new malware loader called Verblecon. The malware is Java-based and its polymorphic nature is what allows it to slip into compromised systems undetected. The oldest sample, for instance, was added to the database on October 16, 2021 – prior to its discovery – is currently detected by nine out of 56 antivirus engines. Newer samples from late January 2022 are almost completely missed by the antivirus engine on VirusTotal. Researchers believe that more sophisticated cybercriminals could use it for ransomware and even espionage attacks.”]

