Las Vegas, August 2, 2024 –Researchers unveil a new method for hackers to hide malicious code using bytecode interpreters, bypassing traditional security measures and posing a significant cybersecurity threat.
In a groundbreaking revelation at the Black Hat USA conference, cybersecurity researchers unveiled a new method cybercriminals use to hide malicious code. By exploiting bytecode interpreters, hackers can effectively conceal their activities from most security software, posing a significant threat to global cybersecurity.
The research team from NTT Security Holdings Corp. and the University of Tokyo demonstrated how they could inject malicious bytecode into interpreters’ memory for popular programming languages like VBScript, Python, and Lua. This technique allows attackers to bypass traditional security measures that typically scan for malicious code.
Toshinori Usui, a research scientist with NTT Security, explained:
Malware often hides its behaviour by injecting malicious code into benign processes, but existing injection-type attacks have characteristic behaviours...which are easily detected by security products. The interpreter does not care about overwriting by a remote process, so we can easily replace generated bytecode with our malicious code.
This method, dubbed Bytecode Jiu-Jitsu,” represents a new cyberattack frontier. Unlike previous methods that rely on precompiled bytecode files, this approach involves inserting malicious instructions directly into the in-memory processes of a running interpreter. This makes it exceedingly difficult for endpoint security tools to detect the intrusion.
“This type of attack is likely to be missed by most security tools, which only scan Python source code (PY) files,” said Karlo Zanki, reverse engineer at ReversingLabs. “It poses yet another supply chain risk going forward.”
The implications are alarming. By exploiting this loophole, hackers can avoid detection and execute their malicious payloads with impunity. The cybersecurity community urges developers and security professionals to implement more robust defences.
Other News At VPNRanks
- Dark Angels Demand Record $75M: Zscaler Reveals Ransomware Surge
- BlankBot Trojan Strikes: Turkish Users’ Finances at Risk
- StormBamboo’s DNS Poisoning Hijacks Software Updates
- Taiwan and Malaysia Team Up Against Cyber Threats
Hey, wait!
Stay informed on the latest privacy updates, cybersecurity insights, and internet freedom news by following VPNRanks news daily! As your primary resource for critical updates in online security, we ensure you’re always in the know. Make VPN Ranks your go-to guide for safeguarding your digital life!