Chinese pirates abuse Microsoft tool to overcome antivirus and wreak havoc


  • Trend Micro has spotted Preta land dodging antivirus in a new attack
  • The deployment of malware checks if the ESET antivirus is installed
  • Malware turn away from legitimate processes to inject a malicious code

A Chinese piracy group followed in Preta and Mustang Panda was spotted using the Microsoft application virtualization injector to dodge antivirus software by injecting malware into legitimate processes.

New research from the Trend Micro threatening hunting team has revealed how the group also used Configuration Factory, a third -party Windows installation manufacturer, to abandon and execute malicious useful loads.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top