Researchers at FireEye pulled back the layers from an attack campaign based on malware looking to dodge analysis by counting mouse clicks to see if it is in a sandbox.
Maintaining high patch levels is step one to blocking the TeamSpy crew, which used old Java and Adobe Reader vulnerabilities as part of their plan to compromise computers.
For the second time in a month, the National Journal has been spotted serving users with malware, according to security researchers. It has since been cleaned.
A recently-discovered sample of the MiniDuke has been traced back to 2011, indicating its cyber-espionage efforts are older than researchers previously thought.
Anti-virus products scan for malware in two ways. They look for sequences of bits that are found in programs that are known to be “evil” (but which are not commonly found in “good” programs)...