Chinese hackers abuse Microsoft APP-v tool to evade antivirus

The Microsoft Application Virtualization Injector tool has been used as a LOLBIN by the Chinese APT hacker collective “Mustang Panda” to insert malicious payloads into legitimate processes in order to avoid detection by antivirus software.

After verifying more than 200 victims since 2022, Trend Micro’s threat researchers, who monitor the threat organization as Earth Preta, found this technique.

Mustang Panda targets government organizations in the Asia-Pacific area, according to Trend Micro’s visibility, and its main assault technique is spear-phishing emails that look like they are from law read more about Chinese hackers abuse Microsoft APP-v tool to evade antivirus.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *