antivirus solutions

Tech Optimizer
July 5, 2025
Cybercriminals are using legitimate software installer frameworks like Inno Setup to distribute malware, taking advantage of its trusted appearance and scripting capabilities. A recent campaign demonstrated how a malicious Inno Setup installer can deliver information-stealing malware, such as RedLine Stealer, through a multi-stage infection process. This process includes evasion techniques like detecting debuggers and sandbox environments, using XOR encryption to obscure strings, and conducting WMI queries to identify malware analysis tools. The installer retrieves a payload from a command-and-control server via a TinyURL link and creates a scheduled task for persistence. The payload employs DLL sideloading to load HijackLoader, which ultimately injects RedLine Stealer into a legitimate process to steal sensitive information. RedLine Stealer uses obfuscation techniques and disables security features in browsers to avoid detection. The Splunk Threat Research Team has developed detection methods focusing on indicators such as unsigned DLL sideloading and suspicious browser behaviors. Indicators of Compromise (IOC): - Malicious Inno Setup Loader Hash 1: 0d5311014c66423261d1069fda108dab33673bd68d697e22adb096db05d851b7 - Malicious Inno Setup Loader Hash 2: 0ee63776197a80de42e164314cea55453aa24d8eabca0b481f778eba7215c160 - Malicious Inno Setup Loader Hash 3: 12876f134bde914fe87b7abb8e6b0727b2ffe9e9334797b7dcbaa1c1ac612ed6 - Malicious Inno Setup Loader Hash 4: 8f55ad8c8dec23576097595d2789c9d53c92a6575e5e53bfbc51699d52d0d30a
Tech Optimizer
June 28, 2025
Windows is the primary target for malware attacks, leading to a focus on antivirus applications for the platform, while macOS users have fewer options. Norton AntiVirus Plus for Mac offers robust cross-platform protection and has received perfect scores from independent testing labs, excelling in phishing protection. It is priced at approximately .99 annually for a single license and .99 for a five-license subscription. Norton supports the latest three macOS versions: Sequoia (15), Sonoma (14), and Ventura (13). The Gen stack, a new antivirus engine, consolidates technology from Norton, Avast, and AVG, ensuring consistent performance. Norton achieved a perfect score of 18 points in independent testing, with a 100% detection rate for Mac malware and Windows-specific threats. It offers flexible scanning options, with quick scans completing in 30 seconds and full scans in 27 minutes. Norton has a 100% detection rate for phishing sites and includes a smart firewall and intrusion prevention system. Its password manager offers basic functions but lacks advanced features. Norton Genie is an AI-based scam detection tool integrated into the ecosystem. The software includes performance improvement tools like File Cleanup and Startup Manager, but privacy components require separate purchases.
Tech Optimizer
June 26, 2025
All About Cookies has announced the winners of its inaugural Editor's Choice Antivirus Awards, recognizing the most reliable antivirus solutions for various user needs. The selection process involved evaluating over 30 antivirus programs through rigorous testing by the editorial team and security experts, focusing on malware detection rates, system performance impact, and features like real-time scanning and phishing protection. The 2025 award winners include: - Best Overall Antivirus: Norton 360 - Best Antivirus & ID Theft Bundle: Aura Antivirus - Best Web Protection Antivirus: TotalAV - Best Value Antivirus: Surfshark Antivirus - Best Mac Antivirus: Avast - Best Scam & Phishing Protection Antivirus: Bitdefender - Best Performance & Speed Antivirus: AVG - Best Antivirus With Unlimited Devices: McAfee - Best Antivirus for Advanced Users: ESET
AppWizard
June 22, 2025
A significant security vulnerability has been discovered in Android's notification system, allowing malicious actors to exploit invisible Unicode characters to open deceptive links without user awareness. Research indicates that this flaw enables attackers to redirect users from seemingly legitimate links, such as "amazon.com," to malicious sites like "zon.com" through the use of zero-width space characters. Major applications including WhatsApp, Telegram, Instagram, Discord, and Slack have been confirmed as vulnerable to this exploit. Attackers can also use this vulnerability to initiate deep links that perform actions like making calls or sending messages without user consent. Traditional antivirus solutions may not detect these threats, as they do not involve conventional malware, highlighting the need for endpoint protection tools that focus on behavioral anomalies. Users are advised to be cautious with notifications and links from unfamiliar sources.
Tech Optimizer
June 17, 2025
Threat actors are using a fileless variant of AsyncRAT, targeting German-speaking individuals with a deceptive verification prompt. This prompt misleads users into executing harmful commands. The malware employs obfuscated PowerShell scripts to operate in memory without creating files on disk, complicating detection by antivirus solutions. The attack begins with a fake verification page prompting users to click "I’m not a robot," which copies a malicious command to the clipboard. This command uses conhost.exe to run a hidden PowerShell instance that retrieves a payload from a remote server. The malware establishes a connection to a command-and-control server and maintains persistence through registry keys, enabling remote control and data exfiltration. Key tactics include stealth execution, in-memory C# compilation, and TCP-based communication over non-standard ports. The campaign has been active since at least April 2025. Indicators of Compromise (IOCs) include: - IP: 109.250.111[.]155 (Clickfix Delivery) - FQDN: namoet[.]de (Clickfix / C2 Server) - Port: 4444 (TCP Reverse Shell Listener) - URL: hxxp[:]//namoet[.]de:80/x (PowerShell Payload) - Registry (HKCU): SOFTWAREMicrosoftWindowsCurrentVersionRunOncewindows (Persistence on Boot) - Registry (HKCU): SOFTWAREMicrosoftWindows NTCurrentVersionWindowswin (Holds Obfuscated Command)
Search