evasion news
4 stories
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Recent reports indicate a significant evolution in ClickFix attack methodologies, with cybercriminals now employing more sophisticated techniques to mask their malicious payloads. The updated tactics reportedly involve the use of DNS TXT records and browser cache pre-fetching, strategies designed to make the early detection of these threats considerably more difficult for security systems and…

Attackers conceal phishing lures using invisible Unicode characters
Threat actors have been observed employing an advanced phishing technique known as ASCII smuggling, which leverages invisible Unicode characters to bypass email security filters. This method, previously noted in AI prompt injection attacks, involves embedding Unicode characters from the Tags block (U+E0000 to U+E007F) to obscure malicious instructions or keywords.

Akira Ransomware Uses Safe Mode to Bypass EDR
An Akira ransomware affiliate recently attempted to deploy ransomware on a victim's network by first rebooting the compromised host into Safe Mode with Networking, a tactic aimed at disabling endpoint detection and response (EDR) tools. While the maneuver successfully bypassed security controls, the ransomware itself failed to execute due to memory constraints within the stripped-down Safe…

Malware Crypting Services Aid Threat Actors in Evading Detection
Cybersecurity researchers have identified a growing market for "crypting" services, which enable threat actors to modify malicious payloads to evade detection by antivirus (AV) and endpoint detection and response (EDR) tools. These services are becoming increasingly sophisticated, offering a range of features beyond basic encryption to complicate analysis and preserve malware usability.