National Cyber Warfare Foundation (NCWF)

MSUpdater


0 user ratings
2024-06-18 15:21:32
blscott

 - archive -- 
MSUpdater is an alternate name for the group known as Putter Panda

MSUpdater is an advanced persistent threat (APT) that targets Microsoft Windows operating systems, particularly older versions such as XP and Vista. It uses various techniques to evade detection by antivirus software, including stealth mode, fileless execution, and encryption of its malicious code. MSUpdater can be used for a variety of purposes, including espionage, cybercrime, or state-sponsored attacks. Its modular design allows it to adapt to different environments and avoid detection by security software.

Techniques, tactics and practices:

MSUpdator uses various techniques such as stealth mode to hide its malicious code from antivirus software. It also employs fileless execution, which means it does not need to write any files on the system's hard drive and can run entirely in memory without leaving a trace. Additionally, MSUpdater encrypts its malware using various encryption algorithms such as AES (Advanced Encryption Standard) or RSA (Rivest-Shamir Adleman). These techniques allow it to evade detection by security software and remain undetected for extended periods of time.



Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.