Skip to main content

Malware can now detect virtual machines, and then go dark like a Cold War spy

One of the more effective ways to counter a malware infection is to make sure that it infects something that can’t have much of an influence on the rest of the system, like a sandboxed virtual machine. However as malware continues to evolve, its creators are now discovering ways to detect whether it is simply wasting its time infecting virtual machines, so it can go after more legitimate targets.

Discovered by Caleb Fenton with security firm SentinelOne (via ThreatPost), this new form of malware is able to sniff out that it currently resides on a virtual machine. Purportedly it does this by analyzing the number of documents on the machine. Low numbers would suggest some form of testing environment, which could tip it off that it’s sandboxed.

Recommended Videos

After making such a discovery, the malware becomes dormant, deliberately hiding itself as best as possible to avoid any detection techniques by potential security staff or automated tools. Although that particular piece of malware may become redundant to the creator at that point, avoiding detection is incredibly important in such a situation.

Related: Warning from police: Never plug in a USB stick you get in the mail

Since security researchers can use virtual machines to learn a lot about a piece of malware without risking any spread of infection, keeping the nefarious software under wraps allows its clones to proliferate in the wild for a little while longer.

In one specific example that Fenton discovered, the malware would search a machine for Microsoft Word documents using the Recent Documents Windows function. If it discovered two or more, it would initiate and download its malware payload. If those files were not found, it shuts down and obfuscates its location to try and avoid detection.

To try and avoid smart security researchers who may have added a number of Word documents to the system to avoid tripping that check, the anti-sandbox malware also detects the IP of the system and cross references it with a known blacklist of security firm addresses. Again, if it finds itself in the belly of the IT security beast, it will halt all actions and try to hide.

Although not exactly unique, these techniques are rather new and represent the next evolution in the ongoing war between white and black hats the world over. Extending the life of malware can go a long way to improving its viability as an attack vector, often more so than simply making the malware harder to stop.

Please enable Javascript to view this content

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
It’s not your imagination — ChatGPT models actually do hallucinate more now
Deep Research option for ChatGPT.

OpenAI released a paper last week detailing various internal tests and findings about its o3 and o4-mini models. The main differences between these newer models and the first versions of ChatGPT we saw in 2023 are their advanced reasoning and multimodal capabilities. o3 and o4-mini can generate images, search the web, automate tasks, remember old conversations, and solve complex problems. However, it seems these improvements have also brought unexpected side effects.

What do the tests say?

Read more
Ray-Ban Meta Glasses are my favorite AI gadget, and they keep getting better
Ray-Ban Meta Glasses worn by Prakhar Khanna.

Meta announced its Ray-Ban AI Glasses in October 2023, and while the company hasn’t launched a successor yet, it has steadily expanded the feature set, turning them into my favorite AI gadget. These are all quality-of-life upgrades that would ideally be released with the next-gen product. But Meta has announced the expansion of Ray-Ban Meta Glasses to more regions and new Meta AI features rolling out starting this week.

I bought a pair of Headliner Meta Ray-Bans in January 2024, and they’ve been my travel companion ever since. It's not because I can record videos while on the go, but because they are the first AI device that doesn’t scream AI. The ambient presence of tech is what makes them special, and they’re only improving, even after 18 months since launch.

Read more
Apple’s low-cost Vision Pro headset could land sooner than expected
A person pinches while wearing an Apple Vision Pro.

Apple’s Vision Pro headset, despite being the most advanced XR gear of its kind, wasn’t quite the roaring success the company may have expected. An asking price worth $3,500 was certainly a deterrent for enthusiasts, but the lack of a full-fledged computing ecosystem built around it was also a lackluster show.

The company has, however, no intention of giving up. On the contrary, Apple is working on a more affordable, watered-down version, and it could arrive sooner than expected. According to Bloomberg, there’s a chance the headset might make an appearance later this year, possibly around the same window as the iPhone 17 series.

Read more