New “Swiss Army Malware” can develop more threats than ever before


The days of specialized malware are slowly coming to an end, as modern variants are being designed to be able to do many things and carry as many features as possible, new research has claimed.
A report from Picus Security analyzing more than 550,000 real-world samples found that “Swiss Army knife malware” – multi-purpose strains capable of performing all kinds of actions, is on the rise.
In fact, a third of all of the malware analyzed for the report carries at least 20 individual Tactics, Techniques, and Procedures (TTP), the report claims. The average malware leverages 11 TTPs, while one in ten has as many as 30 TTPs. Among the most common features are the abuse of legitimate software, lateral movement, and file encryption.
Heavy investing
As per the MITRE ATT&CK adversary behavior framework, command and scripting interpreter is the most prevalent ATT&CK technique, observed in almost a third of all malware samples.
Remote System Discovery and Remote Services have appeared in the research paper’s top ten for the first time, further strengthening the researchers’ conclusion that malware can now abuse built-in tools and protocols in operating systems to evade detection.
Four out of 10 of the most prevalent ATT&CK techniques identified are used to aid lateral movement inside corporate networks, while a quarter are capable of encrypting data.
All of these things have been made possible, Picus’ researchers found, through heavy investing. Ransomware syndicates are “well-funded”, they said, and they’re happy to re-invest those funds back into building even more dangerous malware. Furthermore, advancements in behavior-based detection methods that the defenders use to keep their premises secure have forced cybercriminals into coming up with new solutions.
“The goal of ransomware (opens in new tab) operators and nation-state actors alike is to achieve an objective as quickly and efficiently as possible,” said Dr. Suleyman Ozarslan, Picus Security Co-founder and VP of Picus Labs.. “The fact that more malware can conduct lateral movement is a sign that adversaries of all types are being forced to adapt to differences in IT environments and work harder to get their payday.”
“Faced with defending against increasingly sophisticated malware, security teams must also continue to evolve their approaches. By prioritizing commonly used attack techniques, and by continuously validating the effectiveness of security controls, organizations will be much better prepared to defend critical assets. They will also be able to ensure that their attention and resources are focused in areas that will have the greatest impact.”
Audio player loading… The days of specialized malware are slowly coming to an end, as modern variants are being designed to be able to do many things and carry as many features as possible, new research has claimed. A report from Picus Security analyzing more than 550,000 real-world samples found…
Recent Posts
- Elon Musk says Grok 2 is going open source as he rolls out Grok 3 for Premium+ X subscribers only
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin will suffer a humane death
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010