How Cyber Criminals Hide Malware in .WAV Files

Wav Malware Featured

Hackers have developed many tricks to get their malware payload onto people’s systems. The very idea of a Trojan is a program that appears to do something beneficial but harbors something darker.

These days, hackers have to be a lot sneakier with their attacks. They sometimes hide malware within another innocent file. This is called “steganography,” and we saw the first case of WAV files carrying malware recently.

What Is Steganography?

Steganography is a broad term that covers any time someone hides data within more data. It’s not just a malware term; it’s been around since 440BC!

Wav Malware Message

Steganography is a little different from encryption. With encryption, there’s obfuscation that the recipient must unravel before they can read the message. Steganography isn’t necessarily encoded, just hidden within another piece of data.

Malware developers have used this ancient technique to sneak files past a computer’s security. Antivirus software tends to be lax with files that aren’t associated with viruses, so malware developers sneak in malicious code within these files.

Typically, the file isn’t used to infect the system, as it’s hard to run a program hidden within a file without assistance. Instead, it’s typically used by viruses that have infected a computer already. It can download these innocent-looking files for instructions or files to execute without alerting the antivirus.

In the past, we saw viruses hidden away in images, but we’ve recently seen the first case of a widespread WAV file distribution method.

How WAV Steganography Works

This new method of attack was reported twice this year. In June we saw a report on how a Russian gang called Waterbug was using WAV-based Steganography to attack government positions. Then, another report came in earlier this month saying that this strategy was on the loose again. This time it wasn’t after officials the files were being used by a Monero cryptominer.

Wav Malware Code

In these attacks, the malware would download executables, DDL files, and backdoors in a WAV file. Once the file was downloaded, the malware would dig through its data to find the file. Once it was found, the malware would execute the code, thus adding to its arsenal while keeping its fingerprint small.

How Do You Avoid WAV Steganography Attacks?

Before you start casting a suspicious eye on your album collection, it’s worth remembering that WAV steganography is used by an already-present malware. It’s not used as an initial infection method but as a way for a current infection to further establish itself on a system. As such, the best way to avoid these sneaky attacks is to prevent the initial attack from occurring,

This means following the golden rules of cybersecurity: have a good antivirus installed, don’t download suspicious files, and keep everything updated. This should be enough to keep cryptomining malware at bay and prevent any suspicious audio files from being downloaded onto your computer!

Defending Against the Wave of WAVs

Steganography is nothing new, even in the cybersecurity world. What is newsworthy, however, is the use of WAV files to smuggle in DDLs and backdoors to malware. Now you know what steganography is and how viruses use it to sneak files past an antivirus.

Does this new method of sneaking in malware worry you? Let us know below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe