Antivirus bypass using process injection
One of the central challenges of malware authors is to hide malware from both antivirus software and users. That is not an easy challenge.
Originally, malware authors relied on the simple technique of changing the malware's name to a legitimate filename that would arouse suspicion within the system, such as svchost.exe
or lsass.exe
. This technique worked on ordinary users who lack a basic understanding of and a background in computers and technology but, of course, it did not work on knowledgeable users with an understanding of how operating systems and antivirus software work.
This is where the process-injection technique enters the picture.
What is process injection?
Process injection is one of the most common techniques used to dynamically bypass antivirus engines. Many antivirus vendors and software developers rely on so-called process injection or code injection to inspect processes running on the system. Using process...