Technology

New malware cleverly hides in the Windows event logs

There are several techniques that are theoretically feasible for malware attacks but are never used in practice. But sometimes that changes, according to a new discovery by security researchers at Kaspersky. They found the first malware in the wild that hides its payload in the Windows Event Logs.

Although such a method existed as a possible concept among scientists, such methods are rarely used in practice because they can only be implemented with considerably more effort than the conventional methods, for which numerous tools exist. In which case discovered now a classic malware dropper causes the WerFault.exe file to be copied to C:WindowsTasks. An encrypted binary resource is also stored under the file name wer.dll. This in itself poses no significant damage potential and should not normally be detected by automated routines.

Well camouflaged

The malware only works in combination with code that is also stored encrypted in the Windows event logs. However, if the malicious code becomes active, it can still be found due to the unusual system behavior – this is what happened in the present case. The Kaspersky researchers found out because their guards had hit a customer’s computer.

The analysis found that the malware was likely a highly targeted attack and not malware that was distributed in large numbers. Kaspersky researcher Denis Legezo concludes that the attacker either has extensive knowledge or not exactly cheap commercial tools to run such a campaign. However, he expects similar attacks to become more common in the future, as the procedure for sideloading malware code in the Windows Event Logs has now also been demonstrated on GitHub.

Recent Posts

Xbox Series X25: Price and date of the anniversary console leaked

The new Xbox Series X25 attracts fans with a chic green case in the style…

12 minutes ago

Google Search, Discover and News: New options for personalization

Google is expanding personalization for its search, Discover feed and News. A new interactive button…

13 minutes ago

GTA 6 leaks: Take-Two goes on a hacker hunt with subpoenas

Take-Two and Rockstar are using all possible means against the attackers operating under the name…

14 minutes ago

Exchange Online 2026: Microsoft doubles mailbox storage

Microsoft is doubling the storage space for Exchange Online mailboxes in certain Microsoft 365 Business…

20 minutes ago

Tesla Semi: All details about the European market launch at the IAA 2026

Tesla is preparing the European launch of the Tesla Semi electric truck. In September, the…

21 minutes ago

Netflix: These are the new films and series in September 2026

A number of new films and series are waiting for Netflix subscribers in September. New…

26 minutes ago