MalVirt: .NET Malware Loaders Spread through Malvertising Attacks

Threat Advisories

MalVirt: .NET Malware Loaders Spread through Malvertising Attacks

Threat Level
Attack Report

For a detailed threat advisory, download the pdf file here

Summary

MalVirt is a cluster of virtualized .NET malware loaders are distributed through malvertising attacks that use obfuscated virtualization and the Windows Process Explorer driver to evade anti-analysis and terminate processes. The loaders use obfuscated virtualization and the Windows Process Explorer driver to evade anti-analysis and terminate processes.