Posts

Showing posts with the label AtomBombing

This New Malware Will Soon Start “AtomBombing” U.S. Banks

A new version of Dridex banking malware was detected and it is targeting European banks and it is expected to be used against the U.S. financial institutions in upcoming months. The Dridex 4 incorporates normal usual range of software improvements which we come to expect from this professionally maintained malware. It is also worth noting that it is the first major malware which adopted the new code injection technique called ‘AtomBombing’. The   AtomBombing was explained by researchers at enSilo back in October 2016. It is named so, because of the main use of it is Windows’ atom tables; read/writable stores of data which can be used by multiple applications. The Malicious code can also be written to atom tables, and then it is retrieved and injected into an executable memory space.  The process mentioned above does not require any exploit against Windows since it just makes use of a feature provided by the Windows. Finally, it is just a new code injection technique which is likely to...