New InnoSetup malware is created with each download attempt

  • AhnLab Security Intelligence Center (ASEC) has identified a new type of malware disguised as cracks and commercial tools.
  • This new type of malware differs from traditional malware as it immediately displays an installer UI and initiates malicious activities when the user clicks on the installation button.
  • Unlike the typical method of pre-generating malware for distribution, this malware is generated and delivered in response to user download requests.
  • Each download request results in the creation of a different malicious code with the same functionality but different hash values.
  • The malware can download and execute files based on the response from its command and control (C2) server.

https://asec.ahnlab.com/ko/66982/

No tags for this post.