A Customized Untraceable Malware for RedTeamers
摘要
Building a custom malware, which can evade all signature, heuristics, behavioral, and sandbox analysis has become the recent trends of malware simulation by read teamers. This paper provides a custom in-memory executable malware encrypted using AES algorithm and has six remarkable capabilities with in-memory execution making the disk or file-based scanners irrelevant. The designed malware is able to perform several operations such as cmd reverse shell access, geo-location, exfiltrate files from the documents folder, chrome history URLs, take screenshots, and webcam hijacking. The tests reflect that it goes undetected by several antivirus.