The first month of the year ended with harsh criticism of antivirus software by a former Mozilla engineer. Shortly after, a Chrome engineer joined with an identical position. And now, we find something worse: the possibility of turning antiviruses into malware. That's exactly what Cybellum did with DoubleAgent, a new attack that relies on an official Microsoft tool, and comes with every version of Windows since the release of XP.
The main goal of antivirus software remains the same: to protect the user and their computer. However, threats have multiplied, and in an attempt to cover all angles, their makers have implemented certain techniques that many developers criticize from start to finish. Even user opinions are sharply divided. The debate is no longer about which antivirus to install; now their very usefulness is being questioned. Antiviruses are considered "trusted elements" in an operating system, and if something or someone were to compromise their integrity, it would be a disaster. More than once we've seen databases with bugs that declared system files as threats, leaving computers out of action around the globe. What's next on the list? Taking full control of the antivirus and using it for malicious tasks.
Let's make room for DoubleAgent, an attack published by the Cybellum team, which can be used on any version of Windows starting from XP against a significant number of antivirus products. The story begins with an official tool called Microsoft Application Verifier. Its job is to reinforce security and verify the integrity of third-party applications, but there's a small detail: Application Verifier gives a certain degree of customization in its verifiers. DoubleAgent exploits that customization to carry out a code injection without being detected or blocked by the antivirus, and as if that weren't enough, the technique has persistence, meaning its effects remain even after restarting the computer.
Cybellum confirms that DoubleAgent requires elevated privileges to run, but a malicious agent with sufficient resources could "chain bugs" to obtain them. The two videos show DoubleAgent transforming Norton and Avira into ransomware. Fortunately, developers haven't been idle, and new patches are already on the way. At the same time, Windows Defender has a mitigation technique called "Protected Processes" that makes it immune to DoubleAgent, although it's not exclusive (ESET applies it to its critical processes).