A quarter of all malicious JavaScript is obfuscated

Hackers using concealed packers to avoid detection

JavaScript code on a screen

Hackers obfuscate over 25% of malicious JavaScript code to avoid detection, new research has found.

Analysis of 10,000 malicious JavaScript samples, representing threats like malware droppers, phishing pages, scammers, and cryptominers’ malware, revealed that at least 25% of the examined samples used JavaScript obfuscation techniques to evade detection, according to security researchers at Akamai

Obfuscation makes it harder for humans to understand the code running, but this is not the case for the machine, which will run it as normal.

Researchers said this significant percentage of files indicates continued adoption of obfuscation techniques by cyber criminals that want to stay under the radar.

While hackers use packers to compress and encrypt code to prevent detection, the obfuscated code samples appear similar. This is because the same packers are used, making the code structure similar despite having different functions. 

Researchers gave an example of four pieces of JavaScript code — two phishing codes, one malware dropper, and one Magecart scammer — with the same structure and executing the same obfuscation functionality.

“These four examples are the output of the same unique packer functionality being used to obfuscate any given JavaScript code,” said researchers.

By profiling packers and their functionality, researchers said they could evaluate 30,000 benign and malicious JavaScript files and see that at least 25% of the malicious files used one of five profiled packer functionalities.

Related Resource

How to plan for endpoint security against ever-evolving cyber threats

Safeguard your devices, data, and reputation

Man and woman looking at a laptop in an office building Free download

While many obfuscated code samples appeared to be malicious, the report said  0.5% of the 20,000 top-ranking websites on the web were also using obfuscation techniques.

The researchers found that legit websites use obfuscation for various reasons. Some use it to conceal their client-side code functionality, while others have code that a third-party provider obfuscated. Some also use it to protect sensitive information, like email addresses.

Researchers said this evidence sheds more light on the challenges of detecting malicious JavaScript. It shows that obfuscation alone is not enough to indicate the presence of malicious code.

“The approach for detecting malicious obfuscation requires more advanced machine learning techniques that enable differentiation between malicious and benign obfuscated JavaScript,” said researchers.

“A better approach for detection should be one that uses additional indicators and considers obfuscated code as suspicious till proven otherwise. Indicators can be in the form of website features, like domain age and website popularity rank, or in the form of JavaScript code features, like code size and complexity,” they added.

Featured Resources

Shining light on new 'cool' cloud technologies and their drawbacks

IONOS Cloud Up! Summit, Cloud Technology Session with Russell Barley

Watch now

Build mobile and web apps faster

Three proven tips to accelerate modern app development

Free download

Reduce the carbon footprint of IT operations up to 88%

A carbon reduction opportunity

Free Download

Comparing serverless and server-based technologies

Determining the total cost of ownership

Free download

Recommended

Sophos Intercept X Advanced review: AI-powered protection
endpoint security

Sophos Intercept X Advanced review: AI-powered protection

30 Nov 2021
SMBs urged to update software ahead of Black Friday
e commerce

SMBs urged to update software ahead of Black Friday

25 Nov 2021
US adds dozen Chinese tech companies to trade blacklist
Policy & legislation

US adds dozen Chinese tech companies to trade blacklist

25 Nov 2021
US government warns of increased risk of ransomware over holiday season
ransomware

US government warns of increased risk of ransomware over holiday season

24 Nov 2021

Most Popular

Sabbath hackers are targeting US schools and hospitals
ransomware

Sabbath hackers are targeting US schools and hospitals

29 Nov 2021
Apple's mixed reality headset could debut in 2022
augmented reality (AR)

Apple's mixed reality headset could debut in 2022

29 Nov 2021
Nike to take customers into the metaverse with 'NIKELAND'
virtualisation

Nike to take customers into the metaverse with 'NIKELAND'

19 Nov 2021