October 9, 2018 By David Bisson 2 min read

Threat actors are increasingly using a Delphi packer to shield their binaries from malware classification by antivirus software and other security solutions.

FireEye analyzed several samples carrying the “BobSoft Mini Delphi” signature and determined that the samples were consistent with Delphi code constructs. These findings revealed that the malware binaries had been packed using a Delphi packer.

The enterprise security firm observed the packed samples being dropped in various spam campaigns. One operation used an attached document with malicious macros to download the malware. Another leveraged a document that exploited an equation editor vulnerability to deploy its packed payload.

In its analysis, FireEye came across at least eight malware families using the Delphi packer for their campaigns. Lokibot was by far the most prominent, followed by the Pony downloader and NanoCore. Researchers also spotted a cryptomining threat called CoinMiner using the packer.

How Do Malicious Actors Avoid Malware Classification?

The Delphi packer is just the latest cybercriminal effort to prevent malware from being detected or reverse engineered. Attackers do this by concealing their payloads with code that’s not strictly malicious. In particular, packers use a technique called executable compression to make their files smaller. The Delphi packer adds on to this functionality by monitoring windows and mouse cursor movement for signs of a sandbox environment, in which case it puts itself into an infinite sleep.

Packers aren’t the only services that bad actors use to hide their malware. Malwarebytes noted that cybercriminals also turn to crypters, which use obfuscation or actual encryption to make their payloads undetectable, and protectors, which block reverse engineering attempts.

How to Protect Against Packed Malware

According to FireEye, security professionals can protect their organizations against packed malware by using sandbox environments that model real user behavior. The threat advisory on IBM X-Force Echange advises users to update their antivirus software and verify the legitimacy of any unsolicited email attachment. Finally, security personnel should analyze threat intelligence to learn about the latest packers that are available in dark web marketplaces.

Sources: FireEye, Malwarebytes

More from

The major hardware flaw in Apple M-series chips

3 min read - The “need for speed” is having a negative impact on many Mac users right now. The Apple M-series chips, which are designed to deliver more consistent and faster performance than the Intel processors used in the past, have a vulnerability that can expose cryptographic keys, leading an attacker to reveal encrypted data. This critical security flaw, known as GoFetch, exploits a vulnerability found in the M-chips data memory-dependent prefetcher (DMP). DMP’s benefits and vulnerabilities DMP predicts memory addresses that the…

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today