logo

Bypassing Virtualization and Sandbox Technologies

ID: 75f9aba1-2b4c-5e9b-a796-7866fcbce3aa

STIX ID: report--75f9aba1-2b4c-5e9b-a796-7866fcbce3aa

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-06-20

Date Updated: 2026-05-01

...
...

This report explains a sandbox-evasion technique that checks the number of CPU cores (commonly 1 in many sandbox/VM analysis environments) to decide whether to run malicious payloads; it cites Dyreza banking Trojan usage and notes the technique's inclusion in SET, arguing the method is simple, effective across languages (including PowerShell/Python), and reduces detection by common sandboxing products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.