4 ms·
> Malware that is more stealth-conscious would just stop running without any indication, instead of interacting with external processes. I always wondered if w
by hybridtupel 4y ago
> Malware that is more stealth-conscious would just stop running without any indication, instead of interacting with external processes.
I always wondered if we could just use this against the malware. E.g. just run a useless process which is named/looks like a debugger and the malware stops itself. Of course that's nothing to be relied on on its own but maybe as an additional layer of defense?
- revolvingocelot 4y agoMakes me think of that "weird domain name"-based ransomware mitigation. https://www.theverge.com/2017/5/13/15635050/wannacry-ransomware-kill-switch-protect-nhs-attack https://www.theverge.com/2017/5/13/15635050/wannacry-ransomw...
- dylan604 4y agoor adding a russian language pack to your system. some of these are so silly sounding that they are almost unbelievable on first hearing of them.
- fear-anger-hate 4y agoSome EDRs do stuff like adding russian keyboard layout as an alternative, which stops a fair share of 'malware as service' type stealers.