John Lambert Profile picture
Corporate Vice President, Security Fellow, Microsoft Security Research, johnla(AT)https://t.co/3dGtq71Nby

Dec 29, 2016, 8 tweets

ICYMI here’s a thread on what #agile #malware developers have been up to in their sprints in 2016:👿

Avoid automated sandbox analysis by requiring victims to click to activate payload:

Use strong encryption to be impenetrable to content scanners in transit:

Validate if the malware is running a real endpoint by checking the “Mark of the Web”:

A/B test for effectiveness of lure:

Check multiple machine properties to verify it’s on a real endpoint:

Constantly update the UX and localize it to maximize #MAU/DAU to trick the user:

Check the IP to make sure we’re on the real endpoint and not a security vendor:

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling