Phishing craigslist ā but is it malware?
Malware has traditionally been easy to spot and classify, mainly because it was created to serve a specific nefarious purpose and nothing else. In the ongoing arms race between malware authors and the security industry, stealth and other āin plain sightā technologies are emerging as clear favorites. Case in point is a recent Craigslist phish, disguised as a phone update ā nothing new about malware pretending to be something it isnāt, but thatās not where the story ends. Examining the executable shows that it is nothing more than a RAR self-extracting (SFX) archive ā and thus not inherently malicious. ...