Email-borne polymorphic malware triples
Polymorphic malware is rising sharply as security companies bicker over who offers the best protection.


Email-borne polymorphic malware tripled in September, raising fears over the worth of traditional anti-virus technologies.
The signature-shifting forms of malicious software accounted for 72 per cent of all email-delivered malware over the month, up from 18.5 per cent in August, Symantec.cloud data showed.
Some particularly nasty types of polymorphic malware has been in circulation over the past few years. Virut is one particularly dangerous piece of software that remained in Symantec's top 10 table for malware blocked at the endpoint in September.
Anti-virus technology cannot rely on signatures and heuristics alone.
W32.Sality is another and it took the number one spot this month. Both strains are associated with botnet activity.
The biggest worry for IT departments over this kind of malware is its ability to change its encryption key. This means it can't be spotted by anti-virus products relying on signature-based detection systems.
"This is something that anti-virus technology can sometimes struggle with, and many will employ emulation techniques to allow the malware to partially run in a controlled sandbox environment," Paul Wood, senior intelligence analyst at Symantec.cloud, told IT Pro.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The latest strains of malware identified in the Symantec Intelligence Report for September include mechanisms for changing the start-up code in almost every version of the malware, subtly changing the structure of the code and making it harder for emulators to recognise the code as malicious. Anti-virus technology cannot rely on signatures and heuristics alone."
There is something of a war of words going on in the security industry at the moment about the best protection for modern threats like polymorphic malware.
The old guard, including Symantec, have been accused of using old technologies to solve new problems. In particular, the use of database detection systems has been criticised.
Yet Symantec believes its cloud-based Insight technology is more than capable of helping block zero-day or polymorphic threats, even if it isn't truly real-time.
Insight looks at the "integrity of an executable based on knowledge of its reputation and distribution in the real-world," Wood said. Essentially, the technology still relies on past facts to determine the safety of a file, but it can get hold of those facts fairly quickly to make an assessment.
Some rivals, such as M86 Security, claim this isn't fast enough.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Power stations under attack from long-running hacking campaign
News Dragonfly threat group is ramping up activities, say researchers
By Adam Shepherd
-
Symantec profits surge as firms prop up their cyber defences
News The company also announced plans to sell its web certificate business
By Dale Walker
-
Symantec to pay $4.65 billion to acquire Blue Coat
News Greg Clark to become Symantec CEO, promising new cloud security
By Aaron Lee
-
Symantec ditches reseller guilty of scamming PC users
News Silurian told people they had malware, then sold them Norton Antivirus for $249
By Joe Curtis
-
NATO builds up cyber alliance with Symantec tie-in
News Military industrial link up to fight cyber attacks
By Rene Millman
-
Junk emails fall to their lowest rate in 12 years
News Spam is dropping, says Symantec, but other malware threats are on the rise
By Joe Curtis
-
Kaspersky: "We have never been asked to whitelist malware"
News A company blog has revealed neither government nor any other entity has asked it to stop detecting malware
By Clare Hopping
-
Symantec confirms split into separate security & storage entities
News Storage and security will be separated as Symantec tries to boost sales in both
By Adam Lee