4 ms·
Lots of malware will detect it's running virtualized and change behaviour (generally to "do nothing") and there are mitigations around this detection (removing
by BrainInAJar 9y ago
Lots of malware will detect it's running virtualized and change behaviour (generally to "do nothing") and there are mitigations around this detection (removing virtualbox/vmware specific serial numbers, virtualization drivers, etc) but exploits are hard, they are generally tied to a very specific version of very specific software in order to be successful, versions and products the author can't predict (are the hostile analysts running VMWare? Virtualbox? Xen? Mysteries...) and the target surface is likely very low since most malware is just going to be classified by some overworked junior analyst at an antivirus as "GENERIC.W32.RAT" well before it gets any sort of in-depth analysis and binned.
Ultimately you shouldn't worry about VM escapes by any malware you're likely to come across, they're an academic threat.
Weirdly, as a side effect of the first point, simply installing the virtualbox & vmware drivers on your real actual machine can stop a small subset of malware because it thinks it's running virtualized and shuts down
- SomeStupidPoint 9y agoI don't know that I'd say VM escapes are an academic threat -- more that they're used for targeted attacks and not generic malware (usually). Xen, VMWare, and presumably the others seem to get about 1 escape a year that's a serious vulnerability (and 2-3 other ones that could potentially be, but don't seem easily exploitable). Of course, that's publicly disclosed ones, which means there may be more that we're unaware of.