Coding Malware in Fancy Programming Languages for Fun and Profit

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Apostolopoulos, Theodoros, Koutsokostas, Vasilios, Totosis, Nikolaos, Patsakis, Constantinos, Smaragdakis, Georgios
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912292590845952
author Apostolopoulos, Theodoros
Koutsokostas, Vasilios
Totosis, Nikolaos
Patsakis, Constantinos
Smaragdakis, Georgios
author_facet Apostolopoulos, Theodoros
Koutsokostas, Vasilios
Totosis, Nikolaos
Patsakis, Constantinos
Smaragdakis, Georgios
contents The continuous increase in malware samples, both in sophistication and number, presents many challenges for organizations and analysts, who must cope with thousands of new heterogeneous samples daily. This requires robust methods to quickly determine whether a file is malicious. Due to its speed and efficiency, static analysis is the first line of defense. In this work, we illustrate how the practical state-of-the-art methods used by antivirus solutions may fail to detect evident malware traces. The reason is that they highly depend on very strict signatures where minor deviations prevent them from detecting shellcodes that otherwise would immediately be flagged as malicious. Thus, our findings illustrate that malware authors may drastically decrease the detections by converting the code base to less-used programming languages. To this end, we study the features that such programming languages introduce in executables and the practical issues that arise for practitioners to detect malicious activity.
format Preprint
id arxiv_https___arxiv_org_abs_2503_19058
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Coding Malware in Fancy Programming Languages for Fun and Profit
Apostolopoulos, Theodoros
Koutsokostas, Vasilios
Totosis, Nikolaos
Patsakis, Constantinos
Smaragdakis, Georgios
Cryptography and Security
The continuous increase in malware samples, both in sophistication and number, presents many challenges for organizations and analysts, who must cope with thousands of new heterogeneous samples daily. This requires robust methods to quickly determine whether a file is malicious. Due to its speed and efficiency, static analysis is the first line of defense. In this work, we illustrate how the practical state-of-the-art methods used by antivirus solutions may fail to detect evident malware traces. The reason is that they highly depend on very strict signatures where minor deviations prevent them from detecting shellcodes that otherwise would immediately be flagged as malicious. Thus, our findings illustrate that malware authors may drastically decrease the detections by converting the code base to less-used programming languages. To this end, we study the features that such programming languages introduce in executables and the practical issues that arise for practitioners to detect malicious activity.
title Coding Malware in Fancy Programming Languages for Fun and Profit
topic Cryptography and Security
url https://arxiv.org/abs/2503.19058