News

DoubleAgent Attack Turns Anti-Virus Against System to Hijack PC

A new attack mechanism has been uncovered by Cybellum security researchers that can be used to hijack a PC by injecting malicious computer code via the very thing that people believe is protecting their system: the Anti-virus software. Instead of the typical malware which tries to hide itself, the new attack called DoubleAgent, targets the Anti-virus software and takes control of it.

This attack is made possible because of a 15-year old feature in Windows called Microsoft Application Verifier. Everytime an application is launched, the Microsoft Application Verifier has to verify it. The DoubleAgent attack injects a custom verifier into any application and takes place extremely early into the victim’s boot process. It affects all versions of Microsoft’s Windows operating system. The fix has to come from anti-virus vendors themselves but so far only MalwareBytes and AVG have issued a patch for their anti-virus software. Avast has issued a statement through FossBytes that their anti-virus has already been patched against DoubleAgent earlier this year.

“We were alerted by Cybellum last year through our Bug Bounty program to a potential self-defense bypass exploit. We implemented the fix at the time of reporting and therefore can confirm that both the Avast and AVG 2017 products, launched earlier this year, are not vulnerable. It is important to note that the exploit requires administrator privileges to conduct the attack which is difficult for hackers to achieve. Therefore, in this context, we consider the likelihood of such an attack to be low and Cybellum’s emphasis on the risk of this exploit to be overstated.”

The list of affected vendors are:

  • Avast
  • AVG
  • Avira
  • Bitdefender
  • Trend Micro
  • Comodo
  • ESET
  • F-Secure
  • Kaspersky
  • Malwarebytes
  • McAfee
  • Panda
  • Quick Heal
  • Norton

Cybellum has published videos on their YouTube channel demonstrating the DoubleAgent attack on various popular Anti-virus programs:

Ron Perillo

Disqus Comments Loading...

Recent Posts

Apacer AS2280F4 PCIe Gen5 1TB M.2 SSD Review

Apacer is a leading name for high-performance storage and memory, and now with the release…

9 hours ago

Corsair Launches New RS MAX Series Fans

Corsair already has the enthusiast market taken care of, with one of the most comprehensive…

13 hours ago

NVIDIA RTX Remix Gets DLSS 3.5 With Ray Reconstruction

The wealth of incredible RTX Remix mods has been pretty amazing, as we've seen so…

13 hours ago

SteelSeries Unveils The White Arctis Nova Pro Series Headphones

SteelSeries has always had some of the absolute best gaming headsets on the market, spanning…

13 hours ago

NVIDIA DLSS 3 Comes to EVERSPACE 2 and Gray Zone Warfare

There are now over 500 games and applications that feature RTX technologies, and that number…

13 hours ago

Total War Warhammer III’s New DLC Launches

Total War: Warhammer III is one of those games that have an endless amount of…

1 day ago