Author Topic: DoubleAgent attack  (Read 2350 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
DoubleAgent attack
« on: March 24, 2017, 08:14:53 PM »
Hi
I'm so curious to know what you are doing for DoubleAgent :)
Are you releasing a Hotfix for Avast just like TrendMicro?


A new technique named DoubleAgent, discovered by security researchers from Cybellum, allows an attacker to hijack security products and make them take malicious actions.

The DoubleAgent attack was uncovered after Cybellum researchers found a way to exploit Microsoft's Application Verifier mechanism to load malicious code inside other applications.

That's dangerous for these av's:
Avast (CVE-2017-5567)
AVG (CVE-2017-5566)
Avira (CVE-2017-6417)
Bitdefender (CVE-2017-6186)
Trend Micro (CVE-2017-5565)
Comodo
ESET
F-Secure
Kaspersky
Malwarebytes
McAfee
Panda
Quick Heal
Norton

According to this:
https://malwaretips.com/threads/new-attack-uses-microsofts-application-verifier-to-hijack-antivirus-software.69830/

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: DoubleAgent attack
« Reply #1 on: March 24, 2017, 08:17:25 PM »
Several topics on this already.

From memory of the topics, Avast 17.x.x isn't vulnerable to it.

EDIT: This is just one such topic, https://forum.avast.com/index.php?topic=199290.0.
It is pretty hard to be first on the avast forums.
« Last Edit: March 24, 2017, 08:21:51 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: DoubleAgent attack
« Reply #2 on: March 24, 2017, 08:21:32 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: DoubleAgent attack
« Reply #3 on: March 24, 2017, 08:24:09 PM »
Several topics on this already.

From memory of the topics, Avast 17.x.x isn't vulnerable to it.

EDIT: This is just one such topic, https://forum.avast.com/index.php?topic=199290.0.
It is pretty hard to be first on the avast forums.
Thanks
It's really hard to be the first ;D

REDACTED

  • Guest
Re: DoubleAgent attack
« Reply #4 on: March 24, 2017, 08:24:29 PM »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: DoubleAgent attack
« Reply #5 on: March 24, 2017, 08:30:41 PM »
You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0