Never-before-seen "binary file posing as text file" malware

Jul 27, 2020
28,174
19,219
146

The second stage, dubbed "Emptyspace," is a text file that appears blank to browsers and text editors. However, opening it with a hex editor reveals a binary file that uses a clever encoding scheme of spaces, tabs, and new lines to create executable binary code. Mandiant admits it has never seen this technique used before.

So look out for empty looking text files!
 
  • Like
Reactions: lantis3

mindless1

Diamond Member
Aug 11, 2001
8,846
1,815
136
Seems easily avoidable by not doing what you're not supposed to be doing anyway - don't launch questionable files from a questionable flash drive, then you never get the needed stage 1 malware to begin with.