Utilizing YARA to Find Evolving Malware

No ratings

Presented at CopenhagenCyberCrime 2019 by

YARA rules are often made specifically for a certain variant of a threat using strings from a binary. What happens when the strings simply disappear or become obfuscated? This presentation will highlight key components to building YARA rules for finding newer variants or new versions of malware from the same threat actor, that will last through generations of the malware evolution process.