Winnti's new UNAPIMON tool hides malware from security software
ID: a4ceb300-1617-5ab5-8f93-24e21e3c3312
STIX ID: report--a4ceb300-1617-5ab5-8f93-24e21e3c3312
Feed Name: Bleeping Computer
Threat Score
Trend Micro attributes an ongoing cyberespionage operation called 'Earth Freybug' to Winnti/APT41, describing a novel C++ DLL malware (UNAPIMON) that uses Microsoft Detours to intercept CreateProcessW, start child processes suspended, copy and load DLLs from %User Temp%, detect and remove security-product hooks, then resume execution—allowing malicious payloads to execute undetected after VMTools process injection and DLL sideloading.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
