Never-before-seen "binary file posing as text file" malware

Jul 27, 2020
26,010
17,949
146

The second stage, dubbed "Emptyspace," is a text file that appears blank to browsers and text editors. However, opening it with a hex editor reveals a binary file that uses a clever encoding scheme of spaces, tabs, and new lines to create executable binary code. Mandiant admits it has never seen this technique used before.

So look out for empty looking text files!
 
  • Like
Reactions: lantis3

mindless1

Diamond Member
Aug 11, 2001
8,723
1,735
126
Seems easily avoidable by not doing what you're not supposed to be doing anyway - don't launch questionable files from a questionable flash drive, then you never get the needed stage 1 malware to begin with.