smakme7757
Golden Member
The malware sent to Target or others would have been a hand crafted exploit which means that an AV would not have picked it up. I made an undetectable trojan in about 4 hours (a night) by picking code from the net and mashing it together. I ran it through Virus Total and it came back clean. I'm not a good programmer, but with some techniques I found online I could do it.and for those not running any kind of antivirus/firewall/security patching, to this day and age -
...the underlying question is, if ebay, target, banks and other small/large organizations were compromised at one point for a number of exploits, what makes us think that current/future exploits aren't going to target "less-secure" operating systems/hardware? any kind of security is better than none, even if you're going to run absolutely no AV on a VPN-tunnel router, the VPN is still better than nothing. even the default router firewalls are better than being on straight open DMZ. that is, for baseline usage.
A decent programmer would have no trouble developing a piece of malware used in a spear phishing attack. The biggest problem wouldn't be circumventing the AV it would be how to get the malware to the target.
The only real mitigation technique is to run as a standard user. It's by far the most effective way to negate malware.
Last edited: