DoubleAgent Attack Can Turn Your Antivirus Into an Malware

SHARE:

The DoubleAgent attack can be used to take full control over all the major antivirus software . You ask why this weird name, Well a virus...

The DoubleAgent attack can be used to take full control over all the major antivirus software. You ask why this weird name, Well a virus/malware generally would try to hide from your antivirus as best as possible, But this malware instead of hiding from your Windows Antivirus Software, it plays a patches with windows and your antivirus software and turns your Antivirus Software to play double role of  harming your pc instead of protecting it, DoubleAgent actually attacks the antivirus software itself and take control of your windows antivirus software and turn it into an malware. The security researchers from Cybellum have found this technique that if got in wrong hands can be used by the cyber criminals to hijack your computer very easily.

The DoubleAgent Attack takes advantage of a important feature of Windows, Which is about 15-year-old, And because it's an important feature of Windows itself. It affects all versions of Microsoft Windows and  it can’t be patched for now. The Cybellum's website mentions that most antivirus vendors are still unable to patch this vulnerability. Cybellum has also tested the DoubleAgent on all major antivirus software's available for windows and reported it to there respective vendors. But at the time of writing this, only Malwarebytes and AVG have released a patch to fix this.

Here is the list of Windows Antivirus Software's that are affected by this vulnerability:

  • Avast
  • AVG
  • Avira
  • Bitdefender
  • Trend Micro
  • Comodo
  • ESET
  • F-Secure
  • Kaspersky
  • Malwarebytes
  • McAfee
  • Panda
  • Quick Heal
  • Norton

How exactly DoubleAgent attacks the Antivirus itself?

Whenever you try to run an windows system  application Microsoft Application Verifier, verifies the apps, this lets developers to verify and debug code of the applications. Cybellum researchers discovered that Microsoft allows developers to inject there own custom verifier.dll into any application. This process gives an developer or we can say attacker the ability to inject any DLL into any windows process.

If we talk about the complexity of the attack, DoubleAgent has the ability to modify the functionality of an antivirus and it can turn an windows antivirus software into an malware itself,  Although Cybellum team had there focus only on antivirus software, but researchers have said that the DoubleAgent is not only a threat for security applications but the logic behind this attack also have the ability to corrupt any process even the Windows OS too.

Cybellum have advised that the antivirus company's should use Microsoft's new Protected Processes technic, which was first seen in Windows 8.1. The Protected Processes is a new process that Microsoft made for Windows Defender to make it more safe, The Protected Processes do not let any other apps to inject unsigned code into any process.

You can read more details about DoubleAgent Attack on Cybellum’s website. The DoubleAgent source code is available on GitHub.

While almost all antivirus applications are vulnerable with this attack, Comodo denied that Comodo internet security is affected by DoubleAgent, And Cybellum proved there claim wrong in this video by executing and recording the attack on the Comodo Internet Security in the below video:

DoubleAgent Attack on Comodo Internet Security:


DoubleAgent Attack on Norton Antivirus:


DoubleAgent Attack on Avira Antivirus:


COMMENTS

Name

Android,9,Android Apps,7,Android News,3,Android Tricks,6,Apps/Softwares,7,CashBack/Discount Coupons,13,Cheap Deals,12,Earn Free Paytm Cash,2,Earn Money Online,2,Earning Apps,2,Free Internet/gprs Tricks,2,Free Products Loot,4,Free Recharge Tricks,2,Fun Facts/Viral Stories,2,Hot Deals,12,How To/Tutorials,9,Linux/Hacking,5,Modded Apps,2,News/Stories,4,PC/Windows/Linux,7,Refer & Earn,1,Shopping Offers,12,Social/FB/Whatsapp,6,Technology,6,Tricks & Tips,12,Windows,7,Windows Apps,5,
ltr
item
Earning Central | University Of Tricks: DoubleAgent Attack Can Turn Your Antivirus Into an Malware
DoubleAgent Attack Can Turn Your Antivirus Into an Malware
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrifaJMzvi4Vy5OhhgwDI2Kkas3QmGvbk-gXdvNp05GlrjkJ9Eqw2unX6SH-fXHmb53isNdF9FAcn3d3xuMoGEz04n8rRq0h23iv9Q3RlAVfQa7FqjAdGyEZSRFWyN0vF_y8Fw6RM3kg2t/s640/earning-central-double-agent-attack.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrifaJMzvi4Vy5OhhgwDI2Kkas3QmGvbk-gXdvNp05GlrjkJ9Eqw2unX6SH-fXHmb53isNdF9FAcn3d3xuMoGEz04n8rRq0h23iv9Q3RlAVfQa7FqjAdGyEZSRFWyN0vF_y8Fw6RM3kg2t/s72-c/earning-central-double-agent-attack.jpg
Earning Central | University Of Tricks
https://earningcentral.blogspot.com/2017/03/double-agent-attack.html
https://earningcentral.blogspot.com/
https://earningcentral.blogspot.com/
https://earningcentral.blogspot.com/2017/03/double-agent-attack.html
true
6134988045555821367
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy