Featured Post

Twenty Practical Steps to Better Corporate Governance | The Corporate Secretaries International Association (CSIA)

Twenty Practical Steps to Better Corporate Governance | The Corporate Secretaries International Association (CSIA) Please click the li...

Thursday, May 4, 2017

Financial cybercrime group abuses Windows app compatibility feature

http://ift.tt/eA8V8J

When Microsoft made it possible for enterprises to quickly resolve incompatibilities between their applications and new Windows versions, it didn’t intend to help malware authors as well. Yet, this feature is now abused by cybercriminals for stealthy and persistent malware infections.

The Windows Application Compatibility Infrastructure allows companies and application developers to create patches, known as shims. These consist of libraries that sit between applications and the OS and rewrite API calls and other attributes so that those programs can run well on newer versions of Windows.

Shims are temporary fixes that can make older programs work even if Microsoft changes how Windows does certain things under the hood. They can be deployed to computers through Group Policy and are loaded when the target applications start.

To read this article in full or to leave a comment, please click here

May 04, 2017 at 11:20PM

http://ift.tt/2pKowrf

from Lucian Constantin

http://ift.tt/2pKowrf


No comments:

Post a Comment