Polymorphic Malware
Polymorphic malware changes its own code or packaging on each infection or each build so that no two samples share a file hash or a static signature, while the behaviour stays the same. It defeats hash-based blocklists and forces detection onto behaviour, network indicators and the infrastructure the samples share.
Signature detection works by recognising bytes that have been seen before. Polymorphism is the answer to it: an encrypted payload with a different key each time, a mutating decryption stub, junk instructions inserted at random, a packer that produces a fresh binary per download. The program does exactly the same thing on every machine; it just never looks the same.
The practical consequence is that a file hash identifies one sample, not a family. A feed of hashes from yesterday’s campaign catches yesterday’s binaries. Detection has to move to what does not change: the behaviour once running, the memory image after unpacking, and the domains and addresses the sample contacts.
That is where intelligence regains its footing. A thousand unique hashes that all beacon to the same three domains are one campaign, and the domains are its stable indicators. Hash reputation still has a role, as confirmation when a sample is already known, but it is the network layer that identifies the polymorphic family.
Example
An e-mail campaign delivers 4 000 attachments in a day; 4 000 distinct SHA-256 hashes, none previously seen. Every sample, once opened, resolves one of two domains registered the week before. The hashes are useless as a blocklist; the two domains stop the campaign.
In isMalicious
The file hash lookup at /threat-intel/file-hash answers whether a sample is already known to the hash sources isMalicious aggregates, and a report on the domain or address the sample contacts is where a polymorphic family is actually identified.
Frequently Asked Questions
What is Polymorphic Malware?
Polymorphic malware changes its own code or packaging on each infection or each build so that no two samples share a file hash or a static signature, while the behaviour stays the same. It defeats hash-based blocklists and forces detection onto behaviour, network indicators and the infrastructure the samples share.
How is Polymorphic Malware related to Malware?
Polymorphic Malware and Malware are both key concepts in threat intelligence. Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.
Related Terms
Malware
Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.
Infostealer
An infostealer is malware designed to exfiltrate credentials, cookies, browser sessions, and cryptocurrency wallets from infected endpoints. Infostealer logs are a major source of initial-access credentials sold on criminal markets and linked to follow-on ransomware.
Trojan
A Trojan is malware that disguises itself as legitimate software to trick users into installing it. Unlike viruses, Trojans do not self-replicate; they rely on social engineering. Once installed, they may install backdoors, steal credentials, or drop additional malware.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.