Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Home Depot’s Best Deals: Free DeWalt Tools and Robot Lawn Mower and Robot Pool Vacuum Deals

Lewis Capaldi says he’s working on a new album during TRNSMT’s set

How the top hookup apps show up on your bank statement

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » New Windows Rats Avoid detection for weeks using corrupted DOS and PE headers
Celebrities

New Windows Rats Avoid detection for weeks using corrupted DOS and PE headers

By May 29, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 29, 2025Ravi LakshmananMalware/Windows Security

Windows rats avoid detection

According to new Fortinet research, cybersecurity researchers are removing unusual cyberattacks that have been revered with DOS and PE headers that have corrupted malware.

The DOS (Disk Operating System) and PE (Portable Executable) headers are important parts of Windows PE files and provide information about the executable.

The DOS header makes the executable file backwards compatible with MS-DOS and allows the operating system to recognize it as a valid executable, but the PE header contains the metadata and information needed for Windows to load and run the program.

Cybersecurity

“For weeks, we discovered malware running on compromised machines,” Xiaopeng Zhang and John Simmons said in a report shared with Hacker News of the Fortiguard Incide Response team. “Threat actors were running scripts and PowerShell batches to run malware in window processes.”

Fortinet said that it cannot extract the malware itself, but it has obtained a memory dump of running malware processes and a full memory dump of a compromised machine. It is not clear how malware is distributed, or how widespread the attacks it distributes.

Malware running within the dllhost.exe process is a 64-bit PE file with corrupted DOS and PE headers to challenge analysis efforts and reconstruct payloads from memory.

Despite these failures, cybersecurity companies have further noted that they can dismantle dumped malware within a controlled local configuration by replicating the environment of a compromised system after “multiple attempts, errors, and repeated fixes.”

When malware runs, it decrypts the command and control (C2) domain information stored in memory and establishes contact with the server (“Rash Paper”[.]com “) Newly created threat.

“After launching the thread, the main thread enters sleep state until the communication thread completes execution,” the researcher said. “Malware communicates with the C2 server via the TLS protocol.”

Cybersecurity

Further analysis determined that the malware was a remote access trojan (rat) with the ability to capture screenshots. Enumerate and operate system services for compromised hosts. It can even act as a server waiting for an incoming “client” connection.

“We’re implementing a multi-threaded socket architecture. Every time a new client (attacker) connects, the malware generates a new thread to handle the communication,” says Fortinet. “This design allows for concurrent sessions and supports more complex interactions.”

“By operating in this mode, malware effectively transforms the compromised system into a remote access platform, allowing an attacker to launch further attacks or perform various actions on behalf of the victim.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDeepseek quietly releases the upgraded R1 AI model and escalates competition with Openai
Next Article New York Times and Amazon Inc AI Licensing Agreement

Related Posts

Dua Lipa’s second wedding went from Schiaparelli to Chanel

June 20, 2026

Adria Arjona’s red Roberto Cavalli dress at the ‘Supergirl’ fan event

June 19, 2026

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Home Depot’s Best Deals: Free DeWalt Tools and Robot Lawn Mower and Robot Pool Vacuum Deals

Lewis Capaldi says he’s working on a new album during TRNSMT’s set

How the top hookup apps show up on your bank statement

Are your summer activities over? Kids love this educational app, and it’s only $60 during Deal Days.

Trending Posts

Lewis Capaldi says he’s working on a new album during TRNSMT’s set

June 22, 2026

Goose holds moment of silence for fans who died at MSG concert

June 22, 2026

San Antonio mayor says Ye’s July 4th concert should be canceled

June 21, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.