INTRODUCTION.
Advanced intelligent malware is both a cyberweapon, a cyberattack tool, and a cyberthreat, acting in both offensive (and malicious, or offensive malware) and defensive (antagonistic to the former, known as defensive malware) forms. Defensive intelligent malware has various missions: to neutralize, inhibit, disable, sterilize, block, disable, mitigate, inactivate, proactively predict and prevent, respond to, recover from, and retrospectively repair the negative actions of offensive malware. Defensive malware operates with greater functional capabilities and empowerment in strategies, tactics, intelligence, techniques, procedures, opacity, and invisibility, utilizing the highest level of maturity in all the technologies, strategies, approaches, frameworks, mechanisms, etc., employed. It utilizes redundant artificial intelligence technology ( and all its derivatives: redundancy-based distributed machine learning, synthetic media, digital masks, capabilities to bypass malicious CATPCHA and biometric mechanisms, distributed deep learning, natural language processing (NLP), AI inference engines, deep and convolutional neural networks, expert systems, biometric data swapping, deepfakes (to falsify voices, images, videos, etc.), etc. ), cyber threat hunting, automation based on invisible AI-powered mobile bot agents and playbooks . It employs redundant and distributed technologies for neutralizing and inhibiting malicious strategies and TTPs, and uses data intelligence ( Big Data, Data Analytics ), vulnerability intelligence, and cyber threat intelligence. It combines operations, actions, and procedures for devices, systems, data, applications, networks, objects, fixed or mobile entities, etc. It works with any device (tablet, PC, PLC, smartphone, etc.), operating system (Linux, Windows 10, Solaris, Android 12, iOS 15, etc.), hypervisor, container, chatbot (or virtual assistant; the next frontier of apps, it replaces the keyboard; it keeps the microphone always on; examples: Alexa-Amazon, Siri-Apple, Cortana-Microsoft, Assistant-Google, etc.), language type, even custom ones, etc. It uses ZT (Zero Trust, based on trusting nothing and no one. It requires applying the precautionary-prevention-prudence principle, which implies trusting nothing and only trusting with caution, prudence, and prevention after rigorously checking and verifying everything), and ZK (Zero Knowledge , based on the principle that if an entity has a secret, password, biometric/holographic object, etc., it will provide the other entities with which it can interact/communicate with a public key derived from the secret instead of the secret itself).
Keep in mind that even typing a password can lead to being spied on. Multi-layer encryption/signature/hash, side-channels, malicious anti-cyberforensics, nested subliminal channels, multi-level steganography, cyber-mimicry/multi-domain, redundant transponder transfers, PRNGs, dynamic generation of digital commitments, nested, multidimensional, multi-domain, and redundant C&C, mutual and multi-factor authentication (ZK), etc. Do not confuse identifying with authenticating an entity. Identifying an entity means capturing its username or entity persona. This can be done through facial recognition, fingerprinting, iris scanning, retinal scanning, voice recognition, speech patterns, gait analysis, palm prints, DNA analysis, etc. However, this does not prove that the persona, whether physical, verbal, or otherwise, is who it claims to be, as it can be falsified and created using synthetic media, medical masks, facial surgery, digital masks, holograms, image manipulation, videos, photographs, etc. Authenticating an entity means conclusively proving that the identified entity is who it claims to be. This requires heterogeneous multi-factor (MF) authentication (not just single-mode biometrics, but also information about what it possesses, what it knows, what it is, how it behaves, where it is, when it is, etc.). It is crucial to authenticate in both directions, from one entity to the other and vice versa; this is called mutual authentication . Furthermore, any secrets known by the entities must not be revealed to anyone, as doing so would compromise their confidentiality. This is known as Zero Key (ZK) technology. If an entity needs to authenticate with others, it will only reveal—enter—its public key linked to its secret. According to ThycoticCentrify and Sapio Research, 79% of respondents worldwide engaged in at least one cyber-risk activity during 2020 (actions such as saving passwords in the web browser 33%, connecting to public Wi-Fi 32%, using one password to access different sites 23%, connecting their personal device to the corporate network 23%, sharing credentials/passwords with colleagues 13%, clicking on an email from someone they don't really know 12%, consuming "adult" content, accessing P2P (BitTorrent, eDonkey, Gnutella, Freenet, eMule, Ares, Pichat, Retroshare, etc. in the case of Torrent downloads) and the Dark Web 11%, visiting websites not permitted by the organization's IT department 13%, allowing family members to use work devices 12%, using unauthorized personal devices for work, 1 12%, using a personal password in a work context, 18%, etc.). According to a study by the company Redscan , vulnerabilities are on the rise; 68% do not require user interaction to be exploited (they have low cyber-attack complexity, do not require privileges, do not require user interaction, and are highly confidential), which further facilitates the work of malware, which only has to detect which systems have them and act. Malware takes advantage of all kinds of vulnerabilities , such as: TOCTTOU (Time Of Check To Time Of Use) , a "race condition" vulnerability in Linux and Unix environments; improperly audited apps; software with hidden bugs/flaws; operating systems and web browsers that are not properly updated; inappropriate data exchange via mobile devices; physical loss of mobile devices that expose the organization to cyber risks; inappropriate use of IT/OT resources by employees; cyber incidents related to cloud services offered by third parties; etc. Malware can cyberattack ATMs, for example, via jackpotting (emptying the ATM of cash), software skimming (obtaining card data), network man-in-the-middle attacks (intercepting and/or modifying communications between the ATM and its central service), etc. There is also malware that demands a ransom, such as ransomware (which encrypts data) and doxware (which extracts and steals data to threaten its publication).
STRUCTURE OF ADVANCED INTELLIGENT MALWARE. 
Currently, intelligent malware (offensive and defensive) increasingly integrates payloads, seeds, components, modules, tactics, techniques, procedures, functionalities, feature-gain capabilities, etc., and performs a growing number of tasks:
- Targeting. Code is used to locate and transfer malware to its target(s) (victims if it is offensive malware) and, if it is defensive malware, to search for and transfer neutralization, deactivation, etc. units to the offensive malware it encounters. The search for new targets (primary, secondary, improvised, etc.) can be based on information found locally on the computing device the malware is visiting and can be based on systematic network scanning or wireless operations. Local information can be found in configuration files of various types, containing addresses of other computing devices that can be used for various purposes. Malware distributed via email appears in personal email address books or is sought through text files that may contain email addresses, typically files with extensions such as .txt, .html, .xml, .php, etc. Network scanning typically relies on port scanning (using tools like Nmap, Spyse, and Geekflare; the NBTScan utility searches for open NetBIOS name servers) since malware propagation depends on vulnerabilities such as the presence of a suitable open port that can be contacted. Searching the internet for vulnerable devices (such as passwordless webcams or flawed smart IoT devices) uses device search engines like Shodan (https://www.shodan.io/). These searches can be AI-powered and highly targeted, whether for an individual, a group, or globally.
- Propagation and distribution. Code is used to transfer the malware to the target(s) or victim(s). The means by which propagation occurs can affect the speed and stealth of the malware. Some technologies used are: (i) The use of droppers. Not detected by anti-malware. The use of other malware. (ii) Secondary channel. Some malware requires a secondary communication channel (subliminal, steganographic, hidden wired or wireless) to complete the infection, as is the case with the Blaster malware. Although the exploit uses RPC (Remote Procedure Call), the victim's computing device connects back to the infected device using TFTP (Trivial File Transfer Protocol) to download the malware body, completing the infection process. (iii) Self-transported. The malware is actively transmitted as part of the infection process. For example, the passive malware CRClean uses this type of self-transported propagation. (iv) Embedded strategy. Embedded malware sends itself as part of a normal communication channel, either by adding to or replacing regular messages. As a result, the spread doesn't appear anomalous when viewed as a communication pattern. The embedded propagation strategy is relatively stealthy and makes sense when the target selection strategy is also stealthy. The speed at which embedded malware spreads depends on how the application is used. The distribution of related malware payloads can be one-to-many (when a single site provides malware, a seed, a fragment, or a module to other sites once they have been initially infected. This is the fastest method and prevents "protection entities" from removing the malware source), many-to-many (when multiple fragments or modules propagate the malware, creating massive, global, and widespread waves of infection and contagion), or a hybrid approach(when the malware spreads in a many-to-many with updates received from a single central site).

- Activation. This represents the means by which malware activates on the target device(s). It affects the speed of spread; some malware activates almost immediately, while others can wait for years. Some activation mechanisms are: (i) Auto-activation (auto-run). Malware that activates faster can initiate its own activation by exploiting vulnerabilities in services that are always active and available (for example, exploiting IIS web servers or libraries used by services like XDR). This malware cyberattacks running services or executes other commands using permissions associated with the targeted service. Execution occurs when the malware locates a copy of the vulnerable service and transmits the exploit code. Countermeasures include running non-vulnerable software and limiting access to services that are always active. But beware, what constitutes uninfected software? There are legitimate app storage sites like Google Play, Huawei's AppGallery, etc., where downloading an app can result in the download of a Joker Trojan. (ii)Human activation. Malware must convince a local user (using social engineering techniques, for example, appealing to vanity, greed, urgency, fantasy, financial need, job search, etc.) to run a local copy of the malware. This can happen, for example, by running an attached program, clicking a link, icon, button, or close button (X), watching a video, opening a file, etc. This allows the malware to exploit vulnerabilities in the user's software, load additional malware to control the victim's device, and so on. Human activity-based activation is used by some malware when the user resets a device, closes a window, logs in and runs login scripts, remotely opens an infected file, writes data to the target disk without being able to directly trigger execution, etc. (iii) Activation based on scheduled processes. Many operating systems and applications include auto-updater programs that periodically download, install, and run software/firmware updates. Each version of these systems does not use authentication, so the cyber-attacker/malware only needs to deliver a file to the victim's system to infect it. Other systems periodically run backups and other types of network software that contain vulnerabilities. Sophisticated malware needs to exploit these vulnerabilities. If the targeted tool lacks authentication, a DNS redirect attack may suffice; otherwise, it may be necessary to acquire the private keys of the update server and the code authoring server.
- Payloads (defensive or offensive). Intelligent malware (controllable, autonomous, and updatable) can have one or more hidden payloads (defensive/protective or offensive), can be modular/distributed, and can have its payload encrypted, fragmented, or steganographic. The payload is the code to be executed on the target(s) or victims. It can be multiple and even created ad-hoc (or picked up from the network) without limit. Malware with a payload of no functionality or no payload can still have a malicious effect, as the task of propagating this malware can consume many network resources and cause network slowdowns or a denial-of-service (DoS) attack, for example, the W32.Slammer malware. Payloadscan be of very different types and purposes: (i) Damage/recover data (to perform offensive or defensive actions). Malware can integrate low-level data erasure tools with time delays and data manipulators (such as Klez). Malware can also encrypt data and even distribute sensitive information to sow confusion. (ii) Remote control of the physical world. Malware can affect non-Internet services and objects; for example, networks are also used to control objects in the physical world (such as robots) using, for instance, SCADA (Supervisory Control and Data Acquisition) systems, CPS (Cyber Physical Systems), PLCs, etc. Computing devices can also be used to perform actions on people (directly or indirectly, as in the case of connected vehicles, cyber prostheses/life-saving IoT devices, etc.). “Coercive payloads” may not cause harm unless the malware is attacked. Such malware attempts to remain entrenched, giving the user a choice: “allow the malware to work and suffer no harm, or attempt to remove it and risk adverse results.” (iii) Damage to the physical world (living beings, analog resources, environment). Malware (Chernobyl-style) can include reflashing routines for various types of BIOS. Since flash-ROM memories are soldered to the motherboard, a cyberattack of this type can destroy motherboards when there is no protected BIOS recovery mechanism or other similar mechanism. (iv) Malware maintenance. This is used to enhance the malware (feature gain), improve its ability to damage, defend itself, hide, propagate, or adapt to defensive (defensive malware) or malicious (offensive malware) operations. Mechanisms such as requesting new code from websites (short, medium, or long distance via edge-fog-cloud computing, wired or wireless) and verifying cryptographic integrity before execution are used (feature gain). Similarly, DDoS/DoS tools within zombie/bot malware are also updated. Updatable malware can take advantage of new exploit modules to increase its speed, add sophisticated new functionalities, and debug potential vulnerabilities. (v) Denial of service in the physical world. Malware can be used to deny service (not only to computing devices, applications, and networks in cyberspace) but also in the physical world by using modems to dial emergency services or other critical phone numbers, or by using mechanisms to flood the physical mailboxes of a large number of targets. (vi) Data collection. This type of payload can be used to collect and manipulate sensitive data stored on victim devices (or infected targets). It can perform undetected espionage, surveillance, or data exfiltration by attaching random files to its mailings. It searches for documents with various keywords, credit card numbers, etc. It can also steal identities and, once discovered, encrypts and transmits using various channels (C&C, subliminal channels, etc.) with fault tolerance. Social media malware obtains identities and information from people. Among the purposes of spam is obtaining users' personal information. (vi) Non-functional or with no functionality. In this case, there is no payload. Malware with payload vulnerabilities can overload the victim's device and create traffic, which also has negative effects. (vii) Disruption/Annoyance. In this case, the payload can be used to attract/divert attention and consume computing, network, and human resources (reducing productivity). (viii) Web/HTML Proxy Distribution. This allows redirecting web requests (using DNS) to randomly selected proxy computing devices (either offensive/infected or defensive), making it much more difficult for those protecting against offensive malware to shut down infected/compromised websites used for illegal activities such as scams that attempt to trick users into entering financial data (a technique known as DNS poisoning or pharming). (ix)Spam Relay (Massive Junk Email). It allows the creation of numerous open mail relay devices on the Internet so that spammers can bypass blackhole-based mechanisms that block known spamming IP addresses. (x) Physical world reconnaissance. This type of payload allows the process of scanning telephone numbers to perform tasks with modems (war-dialing). Malware can gain unauthorized access to a modem and perform subsequent reconnaissance in non-Internet-based cyberattacks. (xi) IRC (Internet Remote Control). The malware opens a privileged backdoor that enables the ability to execute arbitrary code. This can allow the issuance of commands, disabling servers, resetting computing devices, etc. (xii) Internet Denial of Service. The malware integrates DoS/DDoS mechanisms to target specific or configurable objectives, allowing the operation of stealthy and encrypted (subliminal-steganographic) channels. Infected devices are called zombies/bots and can cyberattack update sites, response channels, the DNS system, etc. Ransomware (such as WannaCry, Egregor, CryptoLocker, TeslaCrypt, Petya, TorrentLocker, RansomExx, CryptoWall, etc.) causes denial-of-service attacks on files, folders, apps, networks, disks, and computing devices. (xiii) Access for sale. This type of payload is an extension of remote control and data collection. In this case, the malware is granted remote access to specified targets or victims, as desired by the client who pays for these access services. (xiv) Destructive (or retrospective repair; it corrects any malicious modifications if it is defensive malware). It can alter data and fire commands to sabotage vehicles, IoMT, AIoT (which combines AI and IoT; these are AI-powered devices used in industrial automation, agriculture, home automation, smart cities, connected-autonomous vehicles, etc.), the environment, and critical infrastructure. It can delete data from databases and files, perform low-level formatting of hard drives, and act maliciously on cyber-physical systems (in this case, the malware includes knowledge of the potential system and how to control it, etc.). (xv)Disinformation (or the repair of such disinformation if it is defensive malware). Used in cyber-information warfare. They are usually directed against specific systems such as vital resource monitoring centers, document planning systems, cyber-physical monitoring systems, etc. This type of payload has a great potential to control the information of opposition entities. It performs operations such as hiding, creating fake clones (poltergeist cyber-attack), disrupting logistics, disabling equipment, deceiving, concealing, or falsifying the route of vehicles controlled by geolocation. (xvi) Intelligence gathering. All of this can be sent (to vulnerability, cyber-threat, and data intelligence points), to malware operation controllers, to botmasters, etc., for example, using subliminal or C&C (Command and Control) channels. If network connectivity is unavailable, the malware can transmit wirelessly, and the data can be attached to the malware and transported along with the malware code.
- Intelligence, survivability, protection against cyber-forensics, cyber-resilience, fault tolerance, hidden protection entities with cyber-mimicry, and high availability. These elements can be partially distributed among the components mentioned above. It includes invisibility capabilities (based on cyber-mimicry, subliminal channels, steganography, AI, encryption, compression, encoding, virtualization, fragmentation into modules, seeds, etc.), concealability (in unimaginable places such as RAM, printers, routers, SATA hard drives with RAID fault-tolerant mechanisms, steganography, etc.), shape-shifting (with oligo-meta-polymorphism), asymptomatic behavior (eliminating possible clues, traces, anomalies, symptoms, etc., such as changes in speed, length, number of items, shape, time and date, etc.), survival and high availability (with generation of sacrificial decoys, stealthy deployment of multiple malware clones in case of the elimination of some parts to continue the mission), etc. Intelligent malware can be modified so that its properties can change over time. The main properties of intelligent malware are: (i) Multi-component modular design. The various components (seeds, modules, fragments, etc.) work together to carry out highly sophisticated offensive or defensive cyberattacks (in the case of offensive malware) or defensive and protective operations such as deactivation, sterilization, nullification, retrospective repair, etc. (in the case of defensive malware). Some of these components are related to communications ( Bluetooth/BLE, WiFi-6/7, LoRaWAN, NFC/RFID, 5G, etc.). Other more specific components can maliciously control a SCADA (Supervisory Control and Data Acquisition) of critical infrastructure. Still other components allow malware to hide from defenses (antimalware) and survive. (ii) Target-oriented. The specific objectives vary widely depending on the effects of the cyberattack. Examples include espionage, monitoring, and exfiltration (obtaining sensitive information from the target without the owner's permission), sabotage (malware destroys sensitive information, system resources such as hardware, firmware, software, cyberspace data, the environment, living beings, etc.; espionage is conducted before the sabotage to increase the likelihood of its success if it is total), and so on. Defensive malware blocks, neutralizes, or engulfs offensive malware and performs retrospective repairs of any damage. (iii) Detecting defense mechanisms. The success of a malware cyberattack depends on bypassing effective defense mechanisms implemented on the nodes. Offensive malware must detect defense mechanisms and update its behavior to avoid detection during the cyberattack. Defensive malware, on the other hand, hides and does not reveal its existence to the offensive malware. The path of a cyberattack can change flexibly and dynamically, depending on the defense mechanisms detected by the offensive malware or the offensive malware's capabilities against anti-malware. When malware detects a defense mechanism, it uses multiple mechanisms to evade detection (stealth) or it can change the path of the cyberattack. (iv)Use of multiple vulnerabilities. Intelligent malware is modular, dynamic, and distributed, and it can update its modules according to the vulnerabilities of each node. It typically uses multiple vulnerabilities to cyberattack (or perform cyberdefense tasks if it is defensive malware) but can choose only some. The malware's ability to reconfigure itself in real time increases the success of a cyberattack on each specific node. (v)Use of cryptography and steganography. For various purposes, such as hiding, updating, communicating (FOTA/SOTA - Firmware/Software Over The Air), extending the effects of a cyberattack, damaging services/mechanisms, causing node malfunctions, consuming CPU resources of the victim node, data hijacking by encrypting files (as in the case of ransomware), data extraction and threats of publication (as in the case of doxware), etc. (vi) Modularity-Fragmentation. Because intelligent malware is highly sophisticated and modular (containing many components, seeds, fragments, etc.), it can change its objectives for many reasons and is easily modifiable. For example, malware may complete its primary objective and then need to carry out a secondary objective. The malware may require additional capabilities to accomplish the new secondary objective. It can acquire these new capabilities by updating its components, such as adding new components (seeds, fragments) to the infected node. The update process can be initiated by downloading components from both predefined and dynamically generated sources. Because malware capabilities can be modified by updating components, it can be used for different purposes over time, always protecting its undetectability. (vii) Stealth. Malware must conceal its tracks from location-dependent mechanisms (it must modify/delete metadata, logs, geolocation, etc.). Each node may have different defense mechanisms in cyberspace. When malware moves across many nodes, it can use different techniques to hide from each type of node. For example, one node may contain a firewall, while another contains an antimalware program, so the malware needs different mechanisms to hide its tracks. Stealth capabilities make intelligent offensive malware more dangerous than conventional malware and intelligent defensive malware more effective. (viii) Use of multiple languages. Malware can be written in different programming languages. Because malware is considered a cyber-weapon, it can be written in specific languages designed specifically to produce malware with multiple "cyber-munitions." Many physical environments connect to cyberspace and can be controlled remotely using cyberspace. Consequently, malware may require components written in specific languages. For example, some components may be written in dedicated programming languages to control specific physical devices such as PLCs (as is the case with the Stuxnet APT malware components).
NEUTRALIZATION OF OFFENSIVE MALWARE ACTIONS.
Advanced defensive malware is designed to prevent (neutralize, block, etc.) all operations and actions of offensive malware: such as malicious attempts to delete, modify, or gain malicious access (to process/thread data, the Windows registry, the BIOS, all types of internal elements such as PowerShell, etc.), attempts to maliciously hide legitimate data, attempts at malicious encryption such as ransomware, malicious attempts at espionage and data exfiltration, attempts at sabotage and malicious monitoring (e.g., passwords, secrets), attempts at denial of service and slowdown (of systems, networks, devices, operating systems, containers, hypervisors, apps, servers, files, folders, etc.), attempts at privacy violations, and attempts at malicious-illegal occupation of all types of property (computing devices, memory, printers, routers, IoT/IIoT/IoMT, AIoT objects), and hardware (CPUs, GPUs, DSPs, MCUs). AI inference (for AIoT applications), µ-NPUs (Micro-Neural Processing Units), etc.), malicious creation attempts (of files, processes, false or misleading information in accounting records, creation of rogue accounts, creation of partitions, creation of false or misleading information via the web, email, instant messaging, social media, etc.), attempts to perform malicious operations such as (reading, writing, low-level deletion, etc.), etc. To neutralize each malware tactic, its components such as techniques, sub-techniques, procedures, etc., are targeted and each one is disabled or blocked . To prevent/neutralize the initial access tactic , devices using unknown services or when anomalous new connections from an unknown source are observed are neutralized. Connections indicating attempts to exploit public applications by brute force are blocked. Unusual behaviors such as communication with unusual protocols or establishing communication with unexpected devices are blocked. Connections from infected removable media, such as USB drives, are blocked. Malicious access attempts to C&C servers are blocked. Network connections used for malicious activity are blocked. To prevent/neutralize persistence tactics , malicious attempts to create Windows services to disguise themselves as legitimate components are blocked. Malicious attempts to load unvalidated and vulnerable DLLs (Dynamically Linked Libraries) are blocked . Malware payloads hidden within PNG files using steganography are removed. Downloads of firmware programs that create malicious behavior are blocked. To prevent/neutralize execution tactics, malicious API activity is blocked. Malicious traffic accessing the GUI is blocked. Communications with malicious/anomalous traffic, such as Man-In-The-Middle (MITM) attacks, are blocked. Malicious reprogramming attempts from unauthorized devices are blocked. Blocks malicious user behavior such as resets and configuration changes.
To prevent/neutralize evasion tactics, message traffic indicating forged messages is blocked. Attempts to install rootkits by altering configuration and firmware are blocked. Other actions of the defensive malware include blocking unnecessary command-line interpreters originating from offensive malware (acting against the "Command-Line-Interface"); changing Microsoft Office settings to allow Protected View for running within an isolated environment and to block macros via Group Policy; applying application micro-segmentation; disabling unused features or restricting access to scripting engines like VBScript or PowerShell script management macros; blocking certain types of process injection based on common behavioral sequences that occur during the injection process; selectively restricting or disabling NTLM; closing unnecessary ports and services to prevent cyber risks of discovery and exploitation; and disabling PowerShell when not needed. Disable the WinRM service when required to prevent the use of PowerShell for remote execution. Utilize capabilities to prevent malware from accessing credentials, including methods for blocking credential dumping. Deny access to potentially vulnerable or unnecessary software to prevent malware access. Block code execution through app control and/or scripting blocking. Block users or groups from installing unapproved software. Restrict access by configuring directory and file permissions that are not specific to privileged users or accounts. Modify network/host firewall rules to allow only BITS (Background Intelligent Transfer Service) . Limit access to the BITS interface to specific legitimate users or groups. Reduce the default lifetime of BITS jobs (to neutralize persistent malware execution). Close web browser sessions upon completion. Inspect SSL/TLS sessions to ensure that encrypted web traffic is not for malicious activities; if so, block those malicious sessions.
MALWARE CATEGORIES. MACHINE-HUMAN TRANSMISSION-CONTAGION.
malware can be classified into various categories according to different criteria; for example, based on the directionality and nature of the infection endpoints, we can identify the following malware categories:
1 – Malware infection from cyber-entities/cyber-systems to entities (people, living beings) without cyber-implants (cyber-nosis). Malware can transfer (i.e., its harmful and negative effects) from the infected cyber-system to the person and cause harm. For example, malware hidden in a contaminated website, app, QR code, music, movies, video clips, games, a USB drive, etc., can trigger illnesses in people prone to epileptic seizures. In this case, it can trigger an acute epileptic episode if the malware affects the flashing rate, light flickering, and rapid flashing of both the ambient LED light and the background of screens (PCs, smartphones, smart TVs, tablets, etc.) and their content by introducing strobing, vibrant brightness, colors, flashing letters, backgrounds, rapidly changing marks, drawings, photos, sound, etc. in videos, games, websites, etc., processed with tools like synthetic media. Another case is malware that can trigger illnesses in people, such as those prone to heart disease, strokes, and heart attacks. In this case, the malware acts maliciously (changing or accelerating the sound, rhythm, cadence, volume, frequency, and speed to accelerate the victim's heart rate) of music, videos, content, etc., combined with images to cause an accelerated heart rate and lead to cardiac ailments by infecting games, videos, websites, etc., or by redirecting the victim to specific websites. Another example is malware (which operates on audio) that can trigger illnesses in all kinds of people and living beings related to the generation and use of infrasound (for example, with low frequencies from 0.1 to 30 Hz). In this case, the malware maliciously acts on sound and videos from websites, injecting low frequencies that can disrupt and interfere with the signals of brain and physiological functions of the human body, causing dizziness, discomfort, fainting, and even death. Similarly, the injection of subliminal messages and disinformation in video and audio can cause headaches, increased heart rate, suicide, cognitive impairment, depression, etc. There are increasing cases of harm to people caused by CPSs infected with malware. This is the case with all types of vehicles (trucks, buses, cars, ships, airplanes, flying taxis, etc.) connected/autonomous with or without a link to regular smartphones or via satellite. These systems can injure or even kill their occupants or people in the surrounding area when infected by malware (for example, by accelerating the vehicle at full throttle and locking the steering on a curve). The infection can originate from smartphones, apps, USB drives, communications, over-the-air (OTA) updates, etc.
2 – Malware infection from individuals with and without biotechnological cyber-implants/cyber-prostheses to cyber-systems/cybernetic systems. Malware can transfer (i.e., its harmful effects) from a person to a cyber-system (server, connected/autonomous vehicle, PCs, smartphones, tablets, PLCs, etc.). This occurs when a person connects an infected flash drive (for example, an automation drive to a PLC or a music drive to a vehicle) to a cyber-system, downloads an infected attachment, clicks on a malicious link, button, or icon, or visits an infected website directly, through a redirect, or via a malicious QR code, etc. Likewise, System-on-Chip (SOC) and Computer-on-Module (COM) devices, as well as cyber-prostheses (small miniature computing systems with integrated incoming and outgoing communication embedded in living beings for both general operations (IoT/IIoT/AIoT) and medical actions (IoMT) such as pacemakers, cyber-implants to overcome cognitive impairments, brain stimulators, embedded tele-defibrillators, insulin pumps, cochlear cyber-implants, brain cyber-implants, etc.), in addition to being infected by malware, can infect cybernetic devices such as vehicles, household appliances, toys, electricity/water/gas meters, medical instruments, PET scanners, X-rays, ultrasounds, MRIs, robots for operations, personal assistant systems for use in smart cities, smart homes, smart businesses, smart manufacturing, Ambient Intelligence (AmI) environments, etc. There are individuals in companies with cyber-implants in their hands/arms that allow them to manipulate equipment, open/close motors, cylinders, security doors, unlock processes, etc. These implants can be infected and transmit malware to external systems. It is possible to communicate, store, and manipulate data on these cyber-implants, remotely access them, spy on them, change their programming, etc., for example, by using malware-infected OTA (Over-The-Air) updates such as SOTA ( Software-Over-The-Air) and FOTA (Firmware-Over-The-Air)
3 – Malware infection from cyber systems to people with cyber implants (cyber-pathologies). Malware can transfer (i.e., its harmful effects) from the infected cyber system and cause harm to the person/animal with cyber implants. This is the case for living beings dependent on cyber implants such as pacemakers, brain implants (to perform brain stimulation functions, improve the patient's memory or IQ, or treat cognitive impairments, dementia, or other pathologies), cochlear implants (in the ears), cyber-assistants in the pancreas, kidneys, insulin pumps, implanted defibrillator units, etc. These embedded cyber systems (including systems-on-a-chip [SoCs]) can be maliciously disrupted to harm the people and animals that have them. There is a danger of malware infection that could damage the cyber-implant, change its parameters, and even be remotely controlled and access sensitive user information.
4 – Malware infection from cyber-entities/cyber-systems to cyber-entities/cyber-systems. This is the traditional case of spreading the infection and infecting each other among all types of cyber-systems: PCs, smartphones, tablets, vehicles, printers, routers, smartwatches, IoT/IIoT/AIoT objects, robots, avatars, servers, clouds (virtual machines and containers), personal assistants, PLCs, robots, drones, SCADA, databases, CRM, ERP, CPS, etc., using networks, shared infected files, people, personal virtual assistants (chatbots), P2P and client-server networks, etc.
FINAL CONSIDERATIONS.
ZT technology ( Zero-Trust, which means not trusting anything until everything has been thoroughly verified and then exercising caution) allows you to take "complete" control over which software, firmware, and data should be run and block everything else, including any malware. Currently, the number of connected objects/devices is constantly growing in all types of OT/IT environments ( smart homes, financial institutions, businesses, industrial automation (ICS, CPS, SCADA, HMI, DCS, PLC, MES, etc.), wearable devices, clouds (private and public edge-fog clouds, etc.), building automation, cities, homes, robots (social, for industrial automation, underwater, for bomb disposal, surveillance/police, for remote medical operations like Da Vinci, military (anthropomorphic, quadrupedal sniper, etc.), painting/welding, sex robots, etc.), all types of satellites ( reconnaissance, observation, spy, and mapping (like Sentinel-3A/Copernicus, Helios 2A, SAR-Lupe-1-5, Yantar, Almaz, Zenit, Vortex/Chalet, Quasar, PeruSAT1, Zircon, Ofeq-7, PNOTS/Paz, etc.), Spainsat, Sicral, RORSAT-3, Sina-1, Thuraya-1, Asterix, UKRSAT-1, STSAT-2C, KitSat-A, Samos, Lacrosse/Onyx, Cosmo-SkyMed, OPTSAT-3000, etc.), meteorological (such as MTG/Meteosat-3G, MetOp-SG, etc.), telecommunications (such as Hispasat, IRIDIUM, etc.) and internet (such as Google's GeoEye-1, Starlink/OneWeb, etc.)), vehicles (in the automotive world, malware can act on different buses such as CAN-bus, FlexRay, LIN, CAN-FS, etc., on ECUs (Electronic Control Units that manage the operation of the engine, can block the steering, remote control of the heating and air conditioning, can lock or unlock the doors, create chaos in the switching on and off of the warning lights, confuse with the tire pressure (as if (if there were a puncture), locking the windows, activating the airbags, causing forced acceleration and braking, modifying the navigation, blocking the brakes, affecting the entertainment system, manipulating the vehicle's diagnostic log (affecting the driver and repair shops), maliciously downloading driving data (where the driver lives, works, GPS tracking, etc.), etc.), on systems like ADAS (Advanced Driver Assistance Systems) with their sensors, exploiting vulnerabilities and contaminating sensor data so that the malware detects whatever it wants), the OBD2 port (which allows programming, coding, and diagnosing any electronic device incorporated into the vehicle; malware can cyber-attack and control the vehicle (some insurance companies connect a device to this port to lower premiums, which can become infected, to learn the driver's habits), etc. satellites , ). A forecast by the International Data Corporation estimates that there will be 41.6 billion connected IoT devices/objects generating 79.4 zettabytes of data in 2025. According to a Gartner report , the number of IoT devices (and all its derivatives IoMT, IIoT, AIoT, etc.) connected across all technical domains will reach one trillion by 2025. This implies a cyber-malware threat of unimaginable proportions. Malware can cyber-attack everything : virtualization, meaning that virtual instances and virtual machines can spy on and interact with each other; it can distort reality; it can cause a vehicle to get lost due to geolocation failure; malware infiltrated into folders or files allows the geolocation of the person who opens them to be known, etc. A PUF is a function embedded in a physical object such as a chip or integrated circuit that, when asked a challenge z, generates a response w that depends on both the challenge z and the specific physical properties of the device and the unique material of the object containing the PUF (i.e., the unique internal structure of the PUF—it's like its “cyber-DNA”), which is caused by random manufacturing variations; these variations are not recreatable and are not under the control of the manufacturer. PUFs (Publicly Transmitted Functions). PUFs are a good technique for detecting cloned, counterfeit, spoofed, duplicated, etc., hardware, such as preventing the spoofing of video cameras, CPUs, etc. PUF technology is hardware-based and therefore cannot be counterfeited, making the device on which it operates "unique." In contrast, NFT (Non-Fungible Token) entities/objects (files, videos, photos, etc.) are based on blockchain, which is software , and therefore has vulnerabilities. Consequently, the object or entity could be counterfeited and cease to be "unique ." According to Gartner , by 2025 malware will have the absolute capacity to act against all types of OT (Operational Technology) environments to cause injury, contamination, or even death. This is the case with malware cyberattacks on CPS, ICS, vehicles, factories, SCADA, PLCs, etc. A report by RiskRecon and the Cyentia Institute shows that in companies with IoT devices lacking proper configuration and cybersecurity, the risk of such attacks multiplies. Seventy percent of cybersecurity risks to their critical assets are considered critical, and 86% of cybersecurity problems in IoT devices are considered critical.
REFERENCES.
- Areitio, J. “Information Security: Networks, Computing and Information Systems”. Cengage Learning-Paraninfo. 2020.
- Areitio, J. “Controlling the growing empowerment of malware: identification and exploration of key aspects of malware”. Conectrónica Magazine. No. 240. February 2021.
- Areitio, J. “Danger of ignorance of the existence of malware contamination tending towards very serious global cyber-epidemiological situations”. Electronic Journal. No. 241. March-April 2021.
- Areitio, J. “Clarifications on malware, cyber-pandemics and critical cyber-epidemiological scenarios. Protection against malware: early defense”. Conectrónica Magazine. No. 242. May-June 2021.
- Areitio, J. “Confluences between malware, vulnerabilities and exploits: infiltration indicators, infection vector surface and malware danger”. Conectrónica Magazine. No. 243. July 2021.
- Areitio, J. “Adaptation to the variability of undetected malware infection events in all types of current scenarios, environments and ecosystems””. Conectrónica Magazine. No. 244. September 2021.
- Areitio, J. “Duality of advanced intelligent malware (offensive and defensive), points of action and transparent expansion operation”. Conectrónica Magazine. No. 245. October 2021.
- Areitio, J. “Elements and approaches for the design and synthesis of advanced defensive intelligent malware”. Conectrónica Magazine. No. 246. November 2021.
- Astra, JD “Malware”. Shadow Alley Press. 2021.
- DiMaggio, J. “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime.” Not Starch Press. 2021.
- Ryan. M. “Ransomware Revolution: The Rise of a Prodigious Cyber Threat.” Springer. 2021.
- Wardle, P. “The Art of Mac Malware: The Guide to Analyzing Malicious Software.” Not Starch Press. 2021.
- Gupta, BB and Dahiya, A. “Distributed Denial of Service (DDoS) Attacks: Classification, Attacks, Challenges and Countermeasures”. CRC Press. 2021.
- Yehoshua, N. and Kosayev, U. “Antivirus Bypass Techniques: Learn Practical Techniques and Tactics to Combat, Bypass, and Evade Antivirus Software.” Packt Publishing. 2021.
- Calder, A. “The Ransomware Threat Landscape: Prepare for, recognize and survive ransomware attacks.” IT Governance Publishing. 2021.
- Barker, D. “Malware Analysis Techniques: Tricks for the Triage of Adversarial Software”. Packt Publishing. 2021.
- Bilge, L., Cavallaro, L., Pellegrino, G. et al. “Detection of Intrusions and Malware, and Vulnerability Assessment.” 18th International Conference, DIMVA. Springer. 2021.
- Ahmed, A. “Privilege Escalation Techniques: Learn the Art of Exploiting Windows and Linux Systems.” Packt Publishing. 2021.
- Karbab, EB, Debbabi, M., Derhab, A. and Mouheb, D. “Android Malware Detection using Machine Learning: Data-Driven Fingerprinting and Threat Intelligence”. Springer. 2021.
- Boutwell, M. “The Ransomware Handbook: How to Prepare for, Prevent, and Recover from Ransomware Attacks.” Mike Bouwell. 2021.
- Sarwar, FA “Python Ethical Hacking from Scratch: Think like an Ethical Hacker, Avoid Detection, and Successfully Develop, Deploy, Detect, and Avoid Malware.” Packt Publishing. 2021.
- Liska, A. “Ransomware: Understand. Prevent. Recover.” ActualTech Media. 2021.
