This Windows malware turns your PC into a hacker’s punching bag

Malware

Being online just got a tad riskier, for the umpteenth time, thanks to the emergence of a nasty sounding piece of new malware that stealthily avoid detections.

Mylobot, discovered in the wild by Tom Nipravsky, a security researcher at Deep Instinct, is apparently building up a complex botnet, infecting Windows PCs and employs several measures to avoid detection.

The malware can be primed to deliver any number of different payloads, so it could install ransomware or a Trojan, pilfer data, recruit the machine to add firepower to a future DDoS attack – a whole host of unpleasant possibilities are at the malware author’s fingertips.

As for its detection evasion techniques, these include anti-sandboxing routines, disguising its inner workings via encryption, and using a reflective EXE – meaning it executes directly from memory rather than disk, making spotting it harder.

The malware lies dormant for two weeks, doing nothing and keeping a very low profile before finally searching out its command and control server. Stealth is at a premium here, for sure.

Botnet bashing

Interestingly, once active, Mylobot even searches for other botnets on the host PC, and attempts to stop their processes and remove them, effectively barging any competing malware out of the way.

It also shuts down Windows Defender and Windows Update to help make sure it can carry out its nefarious work (whatever that may be) without interruption.

All of which, in short, means this is a highly sophisticated and thus dangerous little beast.

Where did it come from? The origin of the malware remains unknown, as does the intentions of the author, but apparently there is some possible connection to Locky, a famous piece of ransomware, as well as other strains of the latter.

ZDNet reports that Nipravsky observed: “We haven't found any indication about who the author is, but based on the code, this is someone who knows what they're doing.”

Right now, the good news is that Mylobot is far from widespread, although that picture could easily change if the operation behind spreading the botnet is ramped up. And presumably that’s the eventual intention.

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Windows PCs
Dell XPS 13 and Alienware M16 laptops on purple background with big savings text overlay
Dell's site-wide Tech Days sale is live: see the 6 best laptop and gaming laptop deals from just $299
Microsoft presenting Surface Laptop and Surface Pro devices.
Microsoft has pulled a miracle: its Surface Copilot PCs are now the most repairable in the market
asian woman using laptop at business table
Finally, some good Copilot news: Microsoft could be making 16GB RAM a standard for AI PCs
The Acer Predator Orion 3000 gaming PC on a blue and pink background with the text 'TechRadar Cyber Monday PC deals'.
Cyber Monday PC deals 2023 – the best extended deals still live
The Microsoft Outlook logo on a laptop screen
Two unloved Windows 11 apps are getting canned - but will their replacement be any better?
Business man holding a tablet
The PCs protecting workers on the move
Latest in News
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit