Palo Alto Networks’ Unit 42 has revealed multiple sophisticated malware campaigns using advanced encryption and code virtualisation techniques to avoid detection. Attackers are employing the Advanced Encryption Standard (AES) and symmetric keys to encrypt malware payloads. The technique is more difficult to analyse than basic XOR-based obfuscation. Agent Tesla, XWorm, and FormBook/XLoader samples have been found to use these advanced methods, indicating a significant enhancement of malware sophistication.

Trojanized PyPI AI Proxy Steals Claude Prompt, Exfiltrates Data
A malicious PyPI package, hermes-px, that masquerades as a “Secure AI Inference Proxy” while secretly stealing user prompts and abusing a private university AI service.


