Emerging Cyber Threat Tools Capable of Evading Antivirus and Wiping Backups

A recent Digital Forensics and Incident Response (DFIR) investigation has revealed a range of advanced tools used by cybercriminals to circumvent major security systems.

These sophisticated tools have demonstrated their ability to bypass widely used antivirus software like Windows Defender and Malwarebytes. Alarmingly, they can also erase backups and disable essential systems, posing a severe risk to cybersecurity defenses.

Revealed Tools and Techniques

The report highlights several key tools, including Ngrok, which provides proxy services, and SystemBC, known for its stealthy and persistent nature. Additionally, two prominent command-and-control frameworks, Sliver and PoshC2, have been identified as part of the attackers’ toolkit.

These frameworks are infamous for their capacity to enable remote access and control of compromised systems, making them popular among cybercriminals.

The investigation also uncovered an open directory filled with various batch scripts. These scripts, targeting both Windows and Linux platforms, play a critical role throughout the attack process. They are used to disable security protocols, halt vital services, and establish control channels, allowing attackers to maintain their presence within breached networks.

Recent activity involving these tools was detected in August 2024, highlighting the continuous and evolving nature of cyber threats. The capability to bypass antivirus defenses and erase backups marks a significant escalation in cybercriminal tactics.

Organizations are strongly advised to enhance their cybersecurity defenses, ensuring the implementation of robust backup solutions and advanced threat detection mechanisms.

As cyber threats become more sophisticated, staying informed and proactive is essential. This report underscores the importance of vigilance and readiness in the face of evolving cyber challenges.

More Articles & Posts