July 19, 2023, 11:51 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Highlights:



  • Check Point Research (CPR) provides an in-depth analysis of the new malware strain dubbed BundleBot spreading under the radar

  • BundleBot is abusing the dotnet bundle (single-file), self-contained format that results in very low or no static detection at all

  • Commonly distributed via Facebook Ads and compromised accounts leading to websites masquerading as regular program utilities, AI tools, and games

  • CPR introduces several techniques that were approved to be effective for reverse engineering the dotnet bundle (single-file), self-contained format


Introduction …

abusing accounts ads analysis bundle check check point compromised compromised accounts detection distributed dotnet facebook facebook ads file low malware malware analysis own point radar research results single stealer under under the radar websites

Senior Offensive Cyber Analyst

@ PeopleTec | HUNTSVILLE, AL, United States

Cyber Systems Administrator

@ Peraton | San Diego, CA, United States

Senior Security Analyst (SOC)

@ Accesa & RaRo | Cluj-Napoca, Romania

Level 1 SOC Analyst

@ Telefonica Tech | Dublin, United Kingdom

Cyberspace Intelligence Analyst

@ Peraton | Fort Meade, MD, United States

Technical Product Manager, Electronic Warfare

@ Anduril | Costa Mesa, California, United States