Advanced intelligent malware can be viewed from many different perspectives:
(1) As a cyber-weapon (both defensive and offensive). Some examples of offensive malware are: TrickBot, LatentBot, AgentTesla, Gandcrab, Stuxnet, DownPaper, Carbanak, Zeus, Duqu, Ramnit, Wiper, Flame, Babar, Ryuk, Qakbot, ISFB, TurnedUp, Dridex, Goedel, Mosquito, Jaff, Chernobyl, Emotet/Geodo, Pupy, BlackEnergy, Shamoon, DanaBot, etc.
(2) As a sophisticated tool for cyber-attacks (both for protection and for carrying out malicious activities).
(3) As a cyber-threat (for offensive malware, from defensive malware, and to damage our entire world in the case of offensive malware). Currently, in cyber-warfare (which is becoming less and less known), offensive cyber-weapons are used, and the application of protective cyber-weapons (such as defensive malware) is urgent and critical. Their implications are at all levels, in all types of interactions, on all fronts: land (vehicles, robots, tanks, fiber optic communications, etc.), sea (submarines, ships, submarine cables, etc.), air (antennas for telecommunications and terrestrial and satellite internet, commercial aircraft, hypersonic drones, hypersonic missiles against satellites, helicopters, etc.), space (satellites, orbital stations, space probes, asteroid defense, etc.), and cyberspace (which is integrated into the four previous fronts: Internet of Everything/IoE, IoT, APPs, operating systems, clouds, virtual universes/metaverses, cryptocurrencies, websites, hypervisors, OSs, containers, etc.). Defensive malware is autonomous and self-regulating. It is based on AI, ZT, ZK, IAD, TH, dynamic knowledge bases, encryption, subliminal channels, steganography, vulnerability intelligence, etc., and operates at a high level of maturity. The tactical objectives or tactics of offensive malware are the reasons for performing an action. The tactic called "credential access" uses techniques and sub-techniques (which are more or less detailed descriptions for achieving a tactic). In this case, it would involve dumping credentials by accessing Local Security Authority (LSA) services. The procedures (which are the specific implementation of the techniques and sub-techniques) would involve using PowerShell to inject into "lsass.exe" and dump credentials.
MODES OF OPERATION OF OFFENSIVE MALWARE AND THEIR NEUTRALIZATION BY DEFENSIVE MALWARE.
Advanced intelligent malware (both offensive and defensive) can perform its operations, activities, actions, behaviors, etc., in various ways: (1) Passive mode. In this case, offensive malware performs traffic analysis, monitors unprotected communications (fiber optic, copper, wireless, OTA, etc.), decrypts weakly encrypted/authenticated traffic, and captures authentication information (such as passwords, secrets, etc.). Passive interception of network operations can provide offensive malware with indicators and warnings to prevent malicious actions or, in the case of defensive malware, to perform neutralization actions. The passive mode can result in the disclosure of information or data files (such as personal information, tokens, sensitive files, private keys, etc.) to offensive malware without the consent or knowledge of the legitimate user. In this case, defensive malware will neutralize/block all attempts at any type of malicious behavior, operations, and actions. (2) Distribution mode. In that case, the offensive malware makes modifications to hardware, firmware, or software where the asset/product is manufactured or during its distribution (supply chain cyberattack).
In these cyberattacks, offensive malware is introduced into products as backdoors, software Trojans, firmware and hardware, code for planned obsolescence, etc., to gain unauthorized access to information or functions of the system, device, network, etc., at a later date. In this case, defensive malware will scan for malicious behaviors, actions, etc., and neutralize, block, or disable them in advance. (3) Active mode. In this case, offensive malware attempts to bypass or break protection features to steal or hijack data, modify information, etc. Offensive malware cyberattacks the network backbone, exploits information in transit, encrypts folders, penetrates infrastructures (networks, systems, devices, IoT objects, etc.), and cyberattacks authorized remote users when they attempt to connect to an infrastructure, etc. In this scenario, defensive malware will block/neutralize/prevent all types of malicious attempts to reveal, disseminate, or hijack data files; deny service (to networks, systems, devices, applications, etc.); modify data; or carry out sabotage. (4) Insider threat. This can be of two types: (a) Malicious (offensive malware). (b) Motivated by carelessness, accidents, ignorance, forgetfulness, clumsiness, laziness, negligence, unintentional errors, etc., on the part of individuals/entities (who become facilitators of offensive malware). Malicious malware can include attempts at eavesdropping, information theft, data hijacking, data corruption, fraudulent use of information, denying access to other authorized users, sabotage, etc. Those motivated by ignorance, carelessness, forgetfulness, etc. The reasons why individuals/entities might bypass cybersecurity measures are due to accident, laziness, clumsiness, a desire to finish quickly, carelessness, getting the job done, etc. In these scenarios, defensive malware will block and neutralize all types of malware attempts, vulnerabilities, exploits (such as Eternal Blue), etc., and problems related to offensive malware that may have been created by the negligent actions of individuals/entities due to ignorance, carelessness, laziness, forgetfulness, clumsiness, etc. (5) Proximity-based mode. In this case, the offensive malware will be physically close to the targets to be cyberattacked (networks, systems, devices, services, equipment, etc.) with the purpose of modifying, capturing, denying access, sabotaging, etc. This is the case of inserting an infected USB drive into a PC, IPC (Industrial PC), PLC, etc., to sabotage an industrial process, for example, a centrifuge, or a connected/autonomous vehicle to cause an accident or data leak, etc. Proximity can be achieved by using a dishonest or careless employee, forcing entry, breaching security, exploiting an open access point, etc. In this scenario, defensive malware will block and neutralize all types of malicious attempts made by the offensive malware attempting a cyberattack.
NEUTRALIZATION OF THE TACTICAL STRUCTURES USED BY OFFENSIVE MALWARE.
Advanced defensive malware is designed to block, neutralize, disable, mitigate, etc., all possible combinations of tactics (and their internal components: techniques, sub-techniques, procedures, functions, mechanisms, etc.) used by offensive malware. A strong correlation is observed between all structures and knowledge bases of tactics known and synthesized by AI.
Some sets of tactical knowledge bases are (A) EBCT1 (CVCM, LotL, etc.) consisting of the following tactics:
(1) Initial reconnaissance. Offensive malware uses research techniques and procedures on the targets to be cyberattacked (applications, devices, systems, networks, infrastructures, objects, organizations, etc.). Here, defensive malware will paralyze and block all types of malicious research.
(2) Initial compromise. Offensive malware executes malicious code (firmware, software) on one or more targets using reverse engineering, social engineering, etc. Defensive malware will prevent such malicious actions.
(3) Establish a rollback. Offensive malware ensures it maintains its position and retains continuous control over compromised targets (devices, systems, objects, etc.). Defensive malware will block all maintenance and control behaviors on the targets.
(4) Privilege escalation. Offensive malware gains higher privileges/authorizations through various procedures, such as dumping password hashes. Defensive malware will neutralize any malicious technique or procedure.
(5) Internal reconnaissance. Offensive malware explores the target's environment to better understand it. Defensive malware will prevent this.
(6) Lateral movements. Offensive malware uses the credentials obtained in the elevation of privileges to move from one point (device, system, object, etc.) to another within the compromised environment.
(7) Maintaining position. Offensive malware tries to maintain its presence and continuous access to the environment. To do this, it uses different techniques such as installing backdoors, Trojans, etc.
(8) Review of objectives. The mission may be completed or it may continue with other objectives (steal, modify, sabotage, blackmail, kidnap, carry out criminal acts, etc.) on the fly.
Defensive malware will block any further action. (B) EBCT2 (CKC, UKC, GKC, etc.) consists of the following tactics:
(1) Reconnaissance. The malware explores, studies and analyzes its targets, identifying all their vulnerabilities (not only known ones but also 0-day ones).
(2) Armed. The malware adjusts its trajectory to access the targets to be cyber-attacked (objects, devices, systems, networks, infrastructures, etc.).
(3) Delivery. The malware performs the necessary actions to reach the targets and then cyber-attack and infect them.
(4) Social engineering. Malware uses techniques to manipulate people into performing vulnerable actions.
(5) Installation. The malware requires continuous access to its targets; therefore, it installs enabler seeds, backdoors, redundant backup pathways, etc. to reach its objectives. (6) Exploration. The malware executes within the environment and gains the access it needs.
(7) Persistence. The malware makes changes to ensure its continued presence in the system.
(8) Defense evasion. Malware uses techniques to evade detection and bypass other defenses.
(9) Command and Control (C&C). The malware can communicate with controlled systems and other collaborators. (10) Pivoted. The malware tunnels traffic through controlled systems that are not directly accessible.
(11) Discovery. The malware gains knowledge about a target and its environment. (12) Privilege escalation. The malware obtains higher permissions on a target. (13) Execution. The malware can execute code (firmware or software) on a local or remote target.
(14) Access to credentials. Malware accesses or controls targets such as domain credentials.
(15) Lateral movement. Malware accessing and controlling other remote targets.
(16) Collection. The malware identifies and captures data from the remote target before exfiltration.
(17) Exfiltration. Malware extracts information (critical, personal, secrets, private keys, etc.), modifies data, sabotages elements, blackmails, kidnaps, harms humans, the environment, animals, etc. from the targets to be cyber-attacked.
(18) Impact. The malware manipulates, disrupts, or destroys the target.
(19) Objectives. Malware integrates smaller objectives to achieve an overall objective.
(C) EBCT3 (BCs-APT/APR, ET-ICS-MT-IT-OT-ATT&CK, etc.) integrates the following tactics:
(1) Reconnaissance. Integrates the techniques that allow malware to collect information that it can use for future operations.
(2) Resource development. This encompasses the techniques that enable malware to establish resources that can be used to support operations.
(3) Initial access. This encompasses the set of techniques and infection vectors used by malware to enter and obtain an initial position within the network, system, device, etc.
(4) Execution. Integrates the techniques that allow the execution of malicious code on a system, device, local or remote network.
(5) Persistence. This encompasses the techniques malware uses to maintain its position. That is, to enable any access, action, or configuration change on a system, device, or network, thus granting the malware a persistent presence on that system, device, or network. Stolen credentials are often used to create a new account. (6) Privilege escalation. This includes the techniques that generate actions allowing malware to obtain higher levels of permissions and authorizations on a system, device, or network. It can use a valid account to change access permissions.
(7) Defense evasion. Integrates the techniques that malware uses to evade detection or bypass other defenses. It can create a new virtual machine instance to circumvent firewall rules.
(8) Access to credentials. This includes techniques that allow malware to steal account names, passwords, tokens, private keys, or other secrets that grant it access to resources.
(9) Discovery. This integrates the techniques that allow malware to understand its environment and gain knowledge of the system, device, and internal network. For example, it can locate a target database.
(10) Lateral movement. This consists of techniques that allow malware to move through its environment, access and control remote systems on the network and in the cloud (edge, fog, cloud with containers or hypervisors).
(11) Collection. This encompasses the techniques used to collect and identify data of interest and information (such as sensitive files from a target system, device, or network before exfiltration) for their objectives.
(12) Exfiltration. Integrates the techniques that allow malware to steal, extract files, data, metadata and information from a target system, device, network.
(13) C&C (Command & Control). This encompasses the techniques used by malware to communicate with compromised devices and systems to control them within a target network, device, or system, or with its support systems. (14) Impact. This encompasses techniques whose primary purpose is to cyberattack the availability, integrity, authentication, confidentiality, non-repudiation, etc. In this tactic, the malware attempts to manipulate, disrupt, or destroy devices, systems, and data. Defensive malware will neutralize all such attempts.
(14) Network effects. Integrates techniques for intercepting or manipulating network traffic to or from a target (device, system, etc.)
(14) Remote service effects. This encompasses techniques for controlling or monitoring a target using remote services. Very low-granularity associations and correlations based on AI from tactical clusters (and their internal components: techniques, procedures, etc.) allow for predicting and inferring the behaviors and actions of offensive malware that will be neutralized or blocked by defensive malware.
PROBLEM OF OFFENSIVE MALWARE IN CONNECTED AND AUTONOMOUS VEHICLES.
Currently, malware affects all types of systems, networks, metaverses or virtual universes (including Facebook's, with avatars, using virtual reality glasses without a computer connection that can track finger movements for interaction. An earlier predecessor was Second Life, but much less sophisticated), devices (PCs, PLCs, smartphones like the iPhone 13, tablets, etc.), applications/apps, games (of all kinds, for example, the squid game, Axie Infinity, etc.), operating systems (iOS 15, Linux, Android 12, Windows 10, etc.), web browsers (Chrome, Safari, Firefox, etc.), data, metadata, ecosystems, infrastructures, and environments (no one is safe): IT, OT, ICS, CPS, IoT, IIoT, IoMT, AIoT, IoE, AmI, databases, CRM, ERP, clouds (cloud, fog, edge computing), etc. Connected (directly or indirectly) and autonomous vehicles (which are essentially cyber-physical systems) present countless points where malware can act maliciously, even with certifications such as ISO/SAE 21434 and/or UNECE/R155 (no certification can guarantee the absence of potential vulnerabilities in data, software, firmware, hardware, communications, etc.). Over-the-air (OTA) ECU (Electronic Control Unit) management and updates can lead to vulnerabilities, infections, failures, errors, and other issues. ECUs control the majority of a vehicle's functionalities. If malware gains control, it can lock the steering, start/stop the engine, manipulate tire pressure, alter the heating and air conditioning, remotely lock the vehicle, control the navigation system, disable the brakes, maliciously affect the entertainment system, manipulate vehicle diagnostics (changing records), cause forced acceleration or high-speed braking, leak driver data (such as address, work location, driving style, banking information, passwords, and credentials), and remotely control door locks, alarms, and other audible and visual signals. Nothing should be connected to the OBD2 port, as it allows for the programming, coding, or diagnosis of any electronic device in the vehicle. Latent malware (software, firmware, and hardware in the supply chain) can maliciously manipulate the powertrain and the communication language between components (CAN-Bus) by exploiting latent or existing vulnerabilities and flaws. It can unexpectedly cut off communication between two CPUs/chips (this would create disjointed messages from these CPUs, potentially causing serious system failures such as not identifying the speed of nearby vehicles or applying the brakes unexpectedly (even at high speeds) without warning, increasing the risk of rear-end collisions with other vehicles traveling behind). Vulnerabilities are dynamic and can emerge at any time. WiFi (WLAN), 5G (WWAN), LoRaWAN, etc., allow malware to perform malicious actions with photos, videos, and files stored on your smartphone, tablet, PC, etc. (which is often linked to your vehicle). For example, it can monitor you, spy on you, extort you, blackmail you, impersonate you, cause accidents by controlling your vehicle, and so on. Malware can take control of all vehicle safety devices, such as airbags, brakes, engine start/stop, fluid levels, tire condition, steering, heating, hands-free mobile phone connectivity, GPS (providing false data), windows, air conditioning, and audible and visual signals. Malware can also modify the behavior of Advanced Driver Assistance Systems (ADAS), for example, by creating the illusion of an obstacle when none exists ("ghosting") or by simulating the absence of an obstacle when one is present.
Bluetooth (WPAN) allows malware to perform malicious actions using information about your conversations, contacts, messages, confidential data, etc., such as identity theft, harassment, blackmail, reputational damage, and manipulation of vehicle functions. Geolocation (via satellites like GPS, BeiDou, GNSS, GLONASS, Galileo, etc., triangulation by cell towers, or telecommunications satellites like Iridium, etc.) allows malware to manipulate information about your routes, schedules, home and work locations, etc., to carry out malicious actions such as kidnapping, spying on, blackmailing, and deceiving you. The vehicle's key fob and ignition can be manipulated by malware, which can lock you inside the vehicle, prevent you from opening it, steal the vehicle by leaving it unlocked and running, disable/activate the ignition key, and so on. Smartphones and tablets are increasingly being connected to vehicles (which is dangerous) because it means malware can easily transfer between them. Malware can even remotely control when doors are locked or unlocked, the engine is on or off, and even deploy the airbag. Radio Data System (RDS) allows stations to send additional information along with the normal radio program signal displayed on the receiver screen. Malware can create misinformation and chaos. Using synthetic media technology, malware can manipulate the transmitted multimedia data, producing false traffic and accident alerts, providing erroneous information, deceiving, misinforming, confusing, and so on. The emergency call (E-Call) capability in vehicles (based on an embedded system with a SIM card for wireless communication) is activated manually and automatically in case of emergencies. Malware can perform malicious actions by falsifying the exact location of your vehicle to kidnap you, prevent you from receiving assistance in an accident or medical emergency, and so forth. The infiltrated-injected malware acting on the vehicle's opening and starting systems (hands-free type "keyless") makes it easier to steal these vehicles.
Malware infection of the ECU (Electronic Control Unit), responsible for vehicle reliability, can be a critical factor (malware can sabotage the system, isolating two of the many CPUs in a vehicle to create chaos). Malware infection in a vehicle is easier due to the large number of electronic components, software, and firmware, creating a larger attack surface. Malware infection of clouds (public, private, mixed, etc.) where the platforms used by connected vehicles to communicate reside can have a critical effect on these vehicles. A typical vulnerability in connected vehicles allows malware to remotely manipulate certain parameters of the satellite navigation operating system, enabling remote code execution and control of all key vehicle functions. Vehicles with ADAS (Advanced Driver Assistance Systems) may be forced to malfunction if the data streams they process are infected or corrupted by malware. The algorithms incorporated into ADAS systems with machine learning make them vulnerable to new forms of malware cyberattacks. For example, physical/logical changes alter how the vehicle's electronics interpret a situation. The network of ECUs (Electronic Control Units) includes many potential malware attack points that can disrupt the operation of the cyber-physical system. Illegal manipulation of a module during servicing, theft, or sabotage can lead to a denial-of-service attack, preventing the ECU from receiving valid data. The infotainment system can be attacked remotely by malware. Other possible malware attacks include interception, man-in-the-middle (MITM) attacks, and replay attacks (using data previously transmitted over the network). Malware can manipulate driver assistance systems (ADAS), such as lane-keeping assist, which enables the vehicle to maintain its lane position and avoid drifting into the oncoming lane. If malware manages to infiltrate and infect the control system (CAN-BUS) of a connected vehicle or an autonomous vehicle, it could put the vehicle, all vehicles traveling near it, and the manufacturer's data center in a difficult position. Malware (exploiting existing vulnerabilities, including those in connected/autonomous vehicles) can infect, take control of, and manipulate functions that allow it to control various vehicle systems. This includes activating the brakes, locking the steering (at high speed on a curve), maliciously affecting the multimedia system, air conditioning, and infotainment systems, starting or stopping the engine, opening or closing windows/doors, deploying the airbag while driving without a collision, maliciously activating the headlights for hill starts when the vehicle is on a flat surface, maliciously using the vehicle's operating system and browser to make unauthorized purchases, remotely locking/unlocking doors and starting/stopping the engine, activating vehicle braking/acceleration with an infected smartphone/tablet acting as a digital key, opening and starting a car with a keyless device such as a cloned card, opening and starting a vehicle with a cloned remote control, and opening and starting a car with falsified biometrics (facial recognition, fingerprint, etc.). iris, etc.), etc. If malware is introduced into a vehicle via an infected CD, DVD, music USB drive, or through countless other infection vectors, such as an infected smartphone/tablet connected to the vehicle (via Bluetooth-BLE, WiFi, 5G, 6LowPan, LoRaWAN, etc.), or through infection (software, firmware, hardware) in the supply chain, using infected over-the-air (OTA) update downloads, etc. If the malware incorporates "worm" functionality that allows it to replicate itself and spread across networks, it could automatically jump from vehicle to vehicle and even to the manufacturer's data center. Connected vehicles (which have an internet connection to receive system updates) are vulnerable to this threat.
It is capable of receiving and transmitting information to and from the manufacturer's data center databases. This allows the manufacturer to collect data from its vehicles, wirelessly update the vehicle's firmware, and receive or issue service alerts. The manufacturer's data center stores all owner and vehicle data, such as the owner's phone number, name, postal and email address, and driving data, including routes taken, driving style (frequency of braking, distance traveled, routes taken, times, speed limits exceeded, service dates, and any detected vehicle malfunctions). Malware can operate in paid apps integrated into connected vehicles, potentially stealing money, compromising the owner's privacy, and so on. Any vehicle can be cyberattacked by malware on various fronts, including remote control, mobile applications, software/firmware attacks, and physical/hardware attacks, taking advantage of unsuspecting human error, supply chain infections, hardware Trojans, and more. Malware can target hardware ports (USB, OBD2, etc.) and wireless interfaces (Wi-Fi 6/7, IEEE 802.11ax/IEEE 802.11be, 4G, 5G, Bluetooth LTE, ZigBee/IEEE 802.15.4, NFC, Ethernet, LoRaWAN, RFID, etc.). Furthermore, malware can exploit the lack of segmentation in vehicle systems to cyberattack user software using the systems employed for vehicle operation. Malware can infect both user data/metadata generated by vehicle systems and the vehicle's own operational data. Malware can affect the vehicle's brakes, airbags, ignition, and other systems. It can send malicious commands to the CAN-BUS network, which has many functionalities, each vulnerable. Malware can also attack intra-vehicle and inter-vehicle data transmission protocols such as Bluetooth/BLE, Wi-Fi (CSMA/CA), GPS, Ethernet (CSMA/CD), MOST, Zigbee, LoRaWAN, NFC, and others. It can be downloaded remotely and exploit existing vulnerabilities in systems like ignition, steering, acceleration, braking, heating, airbags, doors, lights, and horn. Malware can operate locally or remotely on the vehicle's control unit (ECU), OBD2, ADAS, CAN-BUS network communication, and other components. Malware can send messages with commands to control the vehicle's steering, tires, brakes, and other systems. Malware can be used to sabotage vehicles through over-the-air (OTA) firmware updates, which manufacturers deliver wirelessly and automatically to connected vehicle systems (such as cars, vans, trucks, buses, RVs, etc.). OTA communication can allow for the misconfiguration or uninstallation of valid updates on specific units, potentially leading to accidents. The OTA infrastructure involves various actors: component manufacturers, firmware developers, ECU providers, cloud providers, etc., and these may not all have the same level of cybersecurity controls, potentially harboring latent infections. The OTA infrastructure allows for the remote installation/uninstallation of updates, changes/deletion of vehicle configurations, and other actions. With thousands of chips and millions of lines of code currently present in vehicles, this gives us an idea of the sheer number of vulnerabilities that can exist in a latent state, undetectable by malicious actors. According to Parkers.co.uk, 86% of drivers surveyed would not be comfortable if their car shared data about their driving habits with third parties, and 75% reject data collection systems as the latest technologies being incorporated into the most modern vehicles.
Malware can leave you trapped inside your vehicle with the heater on full blast, doors and windows closed, unable to start the engine, and unable to communicate with the outside world, not even your smartphone, preventing over-the-air updates, etc.
Currently, offensive malware affects all types of systems, ecosystems, and environments (nothing and no one is safe). In OT (Operational Technology), we find ICS, SCADA, CPS, IoT, IIoT, AIoT, IPC, RTUs, IoMT, IoE, IACS (Industrial Automation and Control Systems), cloud computing (cloud, fog, edge computing in automation), etc. In the OT environment, ICS (Industrial Control Systems) are autonomous computing components used in all types of industries: manufacturing, oil refineries, chemical and pharmaceutical processing, power generation, etc., where product creation is based on continuous series of processes applied to raw materials. By deploying and programming ICS components (which in turn integrate CPSs, PLCs, HMIs, MES, SCADA servers, etc.), the different variables of the industrial process can be monitored and controlled remotely; in these scenarios, malware is a reality. A subcategory of ICS is the SIS (Safety Instrumented System), used to protect people, industrial plants, and the environment if a monitored process goes beyond permissible control limits (it is used to stop operations in nuclear infrastructure, oil and gas plants, water treatment infrastructure, etc., when hazardous conditions are detected). These devices are not dedicated to controlling the process itself, but rather to providing a critical emergency signal so that immediate action can be taken if the process control system fails. Again, malware is a reality here. A SIS consists of three elements: (i) Sensor system. These are used to collect the information necessary to determine if an emergency situation exists. The sensors measure process parameters such as temperature, pressure, magnetic field, humidity, flow, radioactivity level, electric field in V/m, and contamination levels such as methyl isocyanate, NO2, SO2, CO, dioxins, 666, etc. (ii) Controllers (resolution logic). They read the sensor signals and execute pre-programmed actions to prevent undesirable situations by providing outputs to the final control elements. (iii) Final control elements. These are actuators such as on-off switches, solenoid valves, speakers, motors, cylinders, relays, horns, alarms, etc., that execute the controller's logical decisions. In 2018, sophisticated malware (called Triton) infiltrated one of Schneider Electric's Triconex SIS systems deployed at a critical infrastructure facility. Various technologies were used to develop this malware, ranging from Windows-based cyberattack vectors to reverse engineering of microprocessor-based firmware and communications. RAT malware is designed to provide complete control over the victim's system; it can be used to steal sensitive information, cyber-spy on the system, remotely control infected devices, generate sabotage, etc.
FINAL CONSIDERATIONS.
One of the techniques used by offensive malware is "Web Injection," which involves intercepting Windows API functions called by the web browser. The process of intercepting a function is called "hooking" (a commonly used function for Web Injection is "HttpSendRequestA"). By intercepting this function, the malware can scan HTTP requests for sensitive and confidential data such as login details (username and password), credit card numbers, private keys, etc., which the malware then uses or sends to a partner organization. Windows APIs are used for malware execution, and fileless execution vectors are implemented using WMI and PowerShell. Defensive malware will neutralize all attempts at such malicious activity.
REFERENCES.
- Areitio, J. "Information Security: Networks, Computing and Information Systems." Cengage Learning-Paraninfo. 2020.
- Areitio, J. “Controlling the growing empowerment of malware: identification and exploration of key aspects of malware.” Conectrónica Magazine. No. 240. February 2021.
- Areitio, J. “Danger of ignorance regarding the existence of malware contamination leading to very serious global cyber-epidemiological situations.” Conectrónica Magazine. No. 241. March-April 2021.
- Areitio, J. “Clarifications on malware, cyber-pandemics, and critical cyber-epidemiological scenarios. Protection against malware: proactive defense.” Conectrónica Magazine. No. 242. May-June 2021.
- Areitio, J. “Confluences between malware, vulnerabilities, and exploits: indicators of infiltration, infection vector surface, and malware danger.” Conectrónica Magazine. No. 243. July 2021.
- Areitio, J. “Adaptation to the variability of undetected malware infection events in all types of current scenarios, environments, and ecosystems.” Conectrónica Magazine. No. 244. September 2021.
- Areitio, J. “Duality of advanced intelligent malware (offensive and defensive), points of action, and transparent expansion operations.” Conectrónica Magazine. No. 245. October 2021.
- Areitio, J. “Elements and approaches for the design and synthesis of advanced defensive intelligent malware.” Conectrónica Magazine. No. 246. November 2021.
- Areitio, J. “Development of advanced defensive intelligent malware.” Neutralization of offensive malware actions." Conectrónica Magazine. No. 247. December 2021.
- Karbab, EB, Debbabi, M. Derhab, A. and Mouheb, D. "Android Malware Detection using Machine Learning: Data Driven Fingerprinting and Threat Intelligence." Springer. 2021.
- Stanford, E. "Crypto Wars: Faked Deaths, Missing Billions and Industry Disruption." Kogan Page. 2021.
- Sanders, C. “Intrusion Detection Honeypots: Detection through Applied Network Defense”.
- Ligh, M.L. “The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory.
” Modern Malware and Next Generation Threats.” No Starch Press. 2019.
- Stamp, M., Alazab, M. and Shalaginov, A. “Malware Analysis Using Artificial Intelligence and Deep Learning”. Springer. 2021.
- Bilge, L., Cavallaro, L., Pellegrino, G. and Neves, N. “Detection of Intrusions and Malware, and Vulnerability Assessment”. 18th International Conference, DIMVA 2021. Springer. 2021.
- Ludwig, M. “The Giant Black Book of Computer Viruses”. American Eagle Books. 2019.
- Mohanta, A. and Saldanha, A. “Malware Analysis and Detection Engineering: A Comprehensive Approach to Detect and Analyze Modern Malware”. Press. 2020.
- Astra, JD “Malware”. Shadow Alley Press. 2021.
- Monnappa, KA “Learning Malware Analysis: Explore the Concepts, Tools, and Techniques to Analyze and Investigate Windows Malware." Packt Publishing. 2018.
