Microsoft Threat Intelligence Profile picture
We are Microsoft's global network of security experts. Follow for security research and threat intelligence.

May 4, 2018, 5 tweets

A couple of fresh malware campaigns in the past few days were halted by Windows Defender AV, whose cloud-based machine learning technologies detected and blocked #Hancitor and #Emotet malware runs at the onset.

The previously unknown #Hancitor and #Emotet variants, which were distributed via email, were flagged by various ML models. Our machine learning technologies combined results from multiple algorithms to correctly determine the malware.

#Hancitor is known for being a sophisticated malware that has been used in targeted attacks in the past and for using unusual APIs and memory injection techniques. #Emotet, on the other hand, is one of the most active banking malware today.

Some of the machine learning models that detected the new malware are predictions from multi-class deep neural networks that also detected and blocked the #BadRabbit ransomware outbreak last year. cloudblogs.microsoft.com/microsoftsecur…

Intelligent systems like this in Windows Defender AV protect customers from malware outbreaks every day. In February, the same ML and AI technologies stopped a similar Emotet outbreak. cloudblogs.microsoft.com/microsoftsecur…

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling