Threat Labs

Notes from the life of the reverse engineering wizards

Decrypted: BianLian Ransomware

The team at Avast has developed a decryptor for the BianLian ransomware and released it for public download. The BianLian ransomware emerged in August 2022, performing targeted attacks in various industries, such as the media and entertainment...

NeedleDropper

Since October 2022, we’ve been observing multiple malware types delivered via a new dropper strain that we are referring to as “NeedleDropper”. Its name references one of the ways the dropper stores data. NeedleDropper is not just a single...

Scripting Arbitrary VB6 Applications

In this paper we will detail a novel way to gain script access to any compiled Visual Basic 6 executable.
This task is accomplished by instrumentation of the runtime and utilizing innate design features of the language.

Hitching a ride with Mustang Panda

Avast discovered a distribution point where a malware toolset is hosted, but also serves as temporary storage for the gigabytes of data being exfiltrated on a daily basis, including documents, recordings, and webmail dumps including scans of...

PNG Steganography Hides Backdoor

Our deep analysis of the Worok toolset (previously described by ESET Research) reveals the final stage, hidden in a PNG file, that steals data and provides a multifunctional backdoor using the DropBox repository and API.

Avast Q3/2022 Threat Report

Cybercriminals actively recruiting and paying people to support their malicious activities Foreword Three months have passed since we published the Avast Q2/2022 Threat Report and here we are again reviewing the cyber threat landscape via the Avast...