Chinese hackers abuse Microsoft Tool to get past antivirus and cause destruction


  • Trend Micro has seen Earth Preta Dodging Antivirus in new attack
  • Malware -Implementation Checks to see if ESET -Antivirus is installed
  • Malware hijacks legitimate processes to inject malicious code

A Chinese hacking group traced as Earth Preta and Mustang Panda has been viewed using Microsoft Application Virtualization Injector to avoid antivirus software by injecting malicious code into legitimate processes.

New research from Trend Micro’s threat -hunting team revealed how the group has also used Setup Factory, a third -party Windows Installer Builder, to fall and performing malicious payload.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top