Security researchers from Cisco Talos discovered a string of malware campaigns that leveraged a decade-old technique for evasion. The technique, known as ‘Heaven’s Gate’, allows malware developed in 32-bit to hide API calls in 64-bit machines. According to the researchers, one of the campaigns distributed the HawkEye Reborn keylogger. Other campaigns mainly spread Remcos, Agent Tesla or cryptocurrency mining trojans.
The big picture
‘Heaven’s Gate’ for attack proliferation
Cisco Talos researchers suggest that the ten-year-old technique might be used extensively to make malware attacks more successful.
“This activity demonstrates how advanced techniques such as Heaven's Gate can be quickly integrated across large portions of the threat landscape. In many cases, the cybercriminals leveraging these kits lack the expertise to implement this type of functionality natively, but can instead leverage available loaders to achieve the same goal,” the researchers wrote.
Publisher