LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
Don’t you hate it when you invest a small fortune in the latest sandboxing technology to protect your network from sophisticated threats, only to find that those same threats are able to evade your shiny new sandbox? We feel you.
The recently discovered Trochilus RAT (Remote Access Trojan) is specifically engineered to evade detection by sandboxing and other more traditional signature-based malware detection techniques. Sandboxing is an advanced antimalware prevention technology that runs unknown or malicious files in a tightly controlled environment either locally or in the cloud, to observe any malicious behavior of the unknown code before allowing it to proceed to its intended target.
Many security vendors have invested heavily in sandbox technology as a cornerstone of their approach to preventing advanced threats in their customers’ networks. The ability of a threat like the Trochilus RAT to defeat even advanced technologies like sandboxing means that their customers can’t rely on prevention to keep threats out.
The AlienVault approach focuses on detection, not prevention, because there is little an organization of any size or IT budget can do to prevent a dedicated, patient attacker from being able to penetrate its network.
The LevelBlue Labs threat research team regularly updates the AlienVault Unified Security Management (USM) platform to detect the behavior of emerging threats like Trochilus on customers’ networks, and how to respond. The Labs team has already released IDS signature and correlation rule updates to the AlienVault Unified Security Management (USM) platform to detect Trochilus activity:
System Compromise, Malware RAT, Trochilus RAT
Current activity in AlienVault Open Threat Exchange (OTX), including related threats: https://otx.alienvault.com/pulse/56939fda67db8c057d6fbf5a/
Arbor Networks ASERT Report on the Seven Pointed Dagger: https://asert.arbornetworks.com/wp-content/uploads/2016/01/ASERT-Threat-Intelligence-Brief-Uncovering-the-Seven-Pointed-Dagger.pdf [Content no longer available]
Kaspersky Labs Threatpost: https://threatpost.com/new-rat-trochilus-skilled-at-espionage-evading-detection/115857/
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.