SLOTAGENT Malware Uses API Hashing and Encrypted Strings to Hinder Reverse Engineering
ID: 078ff980-1a3c-54a7-9df7-a84f3361a993
STIX ID: report--078ff980-1a3c-54a7-9df7-a84f3361a993
Feed Name: cybersecurityNews.com
SLOTAGENT is a newly observed, technically sophisticated malware delivered primarily via phishing attachments that employs runtime API hashing and encrypted strings to frustrate static and dynamic analysis. After silent execution, it establishes C2 communications with minimal network activity to avoid detection, enabling prolonged dwell time for data theft, unauthorized access, and potential secondary payload deployment; defenders are advised to monitor for runtime API resolution behaviors, unusual memory allocations/process injection, suspicious outbound traffic, and to strengthen phishing awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
