Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Developing Immunity Against Zero-Day Mutations
Articles

Developing Immunity Against Zero-Day Mutations

ISBuzz TeamBy ISBuzz TeamAugust 22, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Scott Register at Ixia looks at how the latest malware can be mutated to evade detection by conventional defences, and how businesses can counter the threat.

Everything has to change and adapt to its environment in order to survive, whether it’s a plant, animal, or malicious code developed by cybercriminals.  As new attack techniques are developed to breach networks and steal data, or to encrypt critical files and demand ransoms from victims, security researchers strengthen defenses and introduce new features to counter the emerging threats.  For a short while, criminals may have an advantage until a security solution or feature is made widely available:  then the criminals have to evolve their attack methods to get around the security, and the cycle continues.

An example of this cycle of adaptation and change is the emergence of ‘Zero Day Mutations’ – malware capable of changing itself to evade detection by traditional, signature-based antivirus and IPS systems.  As these signature-based products can only block malware that has alreadybeen analysed and indexed, a variant that is able to mutate itself and change its fundamental characteristics can pass undetected to infect the network.

There’s only a small window of time in which the mutated malware can do this – it usually takes just days or hours for security vendors to identify and issue updates for new attacks – but as long as that window is open, networks’ traditional defensive shields are down.  The Zero Day Mutation technique is frequently applied to ransomware, which is already hard enough for organizations to defend against, because of the insidious way in which it is delivered.  And when the ransomware is capable of mutating, blocking the attack becomes even harder.

The what and how of mutated malware

Our Application and Threat Intelligence (ATI) research team recently analyzed a Zero Day Mutation variant of the Locky ransomware family, which used advanced obfuscation and evasion techniques to avoid discovery by conventional signature-based security products.  In fact, when we discovered the new variant, under 10% of antivirus products were capable of detecting it – which explains why Locky has been the highest-ranked malware threat in the second quarter of 2016.  To understand why this malware has been so effective, let’s take a closer look at how its infection process works.

This latest versions of ransomware use a multi-stage process to infect networks, starting with a targeted phishing email which contains an innocuous-looking document.  The document contains a macro programmed by the attackers to mutate, to help the infection evade detection by signature-based security products.  If the user opens the document, the macro is activated and connects to the attackers’ remote server on the Internet to download the ransomware payload to the user’s machine.  The macro actually rewrites the payload as it downloads – so the file sent across the network is harmless until it hits the user’s PC.  It then starts encrypting the files on that PC (and on other drives the PC is connected to), and demands a ransom.

These multi-stage attacks are especially dangerous, as they are able to bypass detection by virtualized sandboxes, which are often deployed by organizations to block brand-new malware for which signatures have not yet been developed.  Most sandboxes do not flag macros as malicious and further, they only inspect email-based traffic.  Once the macro has been activated on the user’s PC, the malicious payload is delivered by a different route, avoiding the sandbox entirely.

Addressing Zero Day Mutations

However, there is an alternative approach to blocking these Zero Day Mutations which involves both what is being delivered to the network, andwhere that delivery originates from.  This works on the principle that ‘bad’ IP addresses – that is, IP addresses that are known to originate malware, spam hosts, command and control botnets and other tools of cybercriminals – are fairly easy to identify, and that a ‘bad’ IP address very, very rarely switches to become ‘good’ and trustworthy.

This is because IP addresses used on the server side of cybercriminals’ connections are relatively scarce; hackers must either find and compromise an individual server (which may be concurrently used in another criminal campaign), or hijack a range of IP addresses via Internet routing manipulation. These are not simple or easy processes, so IP addresses tend to be continually reused for criminal purposes.  Even brand-new malware variants are invariably connected to a relatively small number of known compromised IP addresses, which totals in the tens of millions out of 4.3 billion IPv4 addresses.

As such, once a malicious IP address is identified, it can be safely filtered and blocked outright from connecting to an organization’s network.  This is done using a threat intelligence gateway that constantly monitors, in real time, both the originating and target IP address for all traffic entering and leaving the network.  It then proactively blocks traffic from malicious IPs, powered by real-time, constantly updated intelligence feeds on addresses that are known to be compromised.

This means that even if a user falls victim to a social engineering email and does open a document containing a macro ransomware downloader, the threat intelligence gateway will prevent the macro from communicating to the IP addresses hosting the Locky payload, nullifying the danger to the user and to the wider enterprise network.  The gateway can also block any attempts by pre-existing, dormant network infections from communicating with external command and control servers.

Conventional defences against malware have focused on what type it is, and how it’s delivered.  Criminals know this, and developed sophisticated Zero Day Mutations that are able to evade those defences.  However, by adding a third detection vector and looking at where the malware originates from, it’s possible to block damaging attacks, and  make networks immune to the newest, most advanced threats.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}