
Malware & Hackers Evade Antivirus with Windows Sandbox
Source: YouTube · John Hammond · published May 30, 2025 · 28:17
The video demonstrates how Windows Sandbox, a security feature in Windows 10/11, has been weaponized by the Mirrorface APT group to bypass antivirus detection 0:00.
Key Takeaways:
• Windows Sandbox is an isolated virtual environment for safely testing files, but Mirrorface malware specifically checks for the WDAG utility account to ensure it only runs within this protected space 1:26
• The sandbox lacks Windows Defender and antivirus protection, making it an ideal environment for malware to operate undetected 5:03
• Attackers can configure Windows Sandbox with WSB files to map host directories, execute commands on startup, and use it as a C2 platform 6:28
• Using WSB.exe command-line tool, attackers can run the sandbox in the background without displaying any visible windows to the user 7:59
Understanding these attack techniques is crucial for defenders to detect and prevent sandbox-based evasion tactics in modern Windows environments.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So, a couple months ago, back in March of 2025, this writeup was released by the Ito Cyber and Intelligence Incorporation in their researcher blog titled Hack the Sandbox, unveiling the truth behind disappearing artifacts. And in this writeup, they discuss a recent malware investigation where the National Police Agency and the National Center of Incident Readiness and Strategy for Cyber Security had previously released a security advisory way back in January regarding an advanced persistent threat attack campaign targeting organizations in Japan by the name Mirrorface. This threat actor, Mirrorface, actually uses Windows Sandbox and Visual Studio Code to carry out their attack. This writeup specifically focuses on the Windows Sandbox attack surface and how it was used, abused, and leverage…