{"id":5276,"date":"2016-09-08T09:12:06","date_gmt":"2016-09-08T01:12:06","guid":{"rendered":"http:\/\/staging.bankvaultonline.com\/?p=5276"},"modified":"2016-09-08T09:12:06","modified_gmt":"2016-09-08T01:12:06","slug":"antivirus-cant-keep-you-safe-researchers-discover-sophisticated-malware-hiding-for-5-years","status":"publish","type":"post","link":"https:\/\/www.bankvault.com\/antivirus-cant-keep-you-safe-researchers-discover-sophisticated-malware-hiding-for-5-years\/","title":{"rendered":"Antivirus can\u2019t keep you safe: researchers discover sophisticated malware hiding for 5 years"},"content":{"rendered":"
One of the underlying assumption for why people use BankVault is that they don\u2019t or can\u2019t trust that their devices are free from infection\u2014not enough for financial transactions.<\/p>\n
It\u2019s a reasonable assumption to make. You\u2019ll typically see studies claiming between 10 and 30 percent of all computers have malware infections.<\/p>\n
The data for these studies are generally gathered from security vendor scans of customer networks or from companies that test antivirus software. The point these studies really emphasise is that the volume and variety malware is growing exponentially.<\/p>\n
A more realistic indication of your own computer\u2019s likely infection will depend on how well it is protected and updated.<\/p>\n
What would be really useful to know is the percentage of well-maintained, up-dated and secured computers that are infected. Or the number of computers that are infected by malware types we don\u2019t yet know about.<\/p>\n
Those would be alarming statistics because most people assume that if they have paid for antivirus and keep their computer updated, they should be safe. Unfortunately, it doesn\u2019t. More and more malware bypasses antivirus software.<\/p>\n
Exemplifying this, researchers have recently discovered<\/a> advanced malware which stayed hidden on a computer for 5 years. Most likely the product of a sophisticated nation-state creators, the malware used unique operations each time to avoid detection by patterns. It included approximately 50 modules which allowed it to be easily managed and customised.<\/p>\n Dubbed “Project Sauron” by researchers at Kaspersky Labs and “Remsec” by Symantec, the purpose of the malware seems to be to obtain passwords, cryptographic keys, configuration files and IP addresses from targeted organisations such as governments, scientific research centres, defence organisations, telcos and financial institutions.<\/p>\n It\u2019s a fascinating example of where the attack landscape is heading. But consider this: now that it has been discovered, it won\u2019t be long until it is adapted and recycled by other attackers for less patriotic purposes.<\/p>\n Another interesting feature of this malware is that it\u2019s designed to remain hidden on computer disk drives and transfer itself to any USB drive plugged in, without detection. It can therefore could even hack data on air-gapped computer networks\u2014computers that are completely disconnected from the internet! It’s an incredible discovery, showing precisely why you cannot entirely trust the computer you’re working on.<\/p>\n So with malware increasingly effective at targeting computers and avoiding detection, surely an alternative approach makes sense?<\/p>\n That\u2019s what we think too. BankVault moves the goalposts so none of this matters.<\/p>\n Think of it this way. If it was possible, the smart approach would to buy a brand new computer each time you went online, use it once, and then discard it in case it was infected.<\/p>\n That is essentially what BankVault does. It builds a pristine new virtual PC at a random Internet address which you use to login to your bank. Your normal (potentially infected) PC stays completely shut off during the process.<\/p>\n BankVault is a very simple approach, but fundamentally different to the detection and prevention approaches of any other antivirus or security product\u2014and that\u2019s why it\u2019s so effective.<\/p>\n BankVault doesn\u2019t try to detect or block malware, it sidesteps the attack<\/a> by moving your critical activity somewhere temporary, secret and safe, negating whatever the attacker might have (or have not) done to your PC.<\/p>\n