Site navigation

Malware Can Now “Play Dead” to Evade Security

Tom Quinn

,

malware
“Attackers no longer need to lock your data to monetise it, they just need to steal it,” said Dr. Süleyman Özarslan, Picus Labs.

Malware is now doing maths and playing dead, according to a new report from Picus Security, which argues we have entered a chilling new era in cyber warfare – the rise of “Digital Parasites”.

Analysing over 1.1 million malicious files and 15.5 million actions over the last year, Picus’ Red Report 2026 discovered that hackers and ransomware gangs are no longer running smash-and-grab attacks, instead shifting 80% of their tradecraft to stealth and persistence.

Researchers uncovered highly sophisticated malware displaying some disturbing, never-before-seen characteristics, which allowed the malicious software to linger within systems for months without detection.

The LummaC2 strain, for instance, was observed using trigonometry, calculating Euclidean distance of mouse angles to distinguish between human users and automated security sandboxes.  

If the mouse moved too perfectly, the malware knew it was being watched and refused to detonate.

Perhaps worse, the study also revealed a new “play dead” tactic deployed by malware to detect and bypass virtualised or sandboxed environments commonly used by security teams for threat detection.

Here, the malware actively checks for indicators of analysis environments, like VM artifacts in hardware, registry entries, or system configurations that would stop or suppress its actions, and if it finds them, it goes dormant. 

The report also found that for the third consecutive year, process injection was the top technique used by attackers, providing them cover to hide code and run malicious payloads under the guise of legitimate applications, making it harder for security tools to detect their activity.

Dubbing these evasive malware strains “digital parasites”, Picus warned that traditional static assessments and assumption-based coverage are not enough as malware grows smarter, and can’t against stealth centred tactics.


Recommended reading


This shift toward quieter, low-profile attacks extends to ransomware gangs, too, with the study observing a 38% drop in “data encrypted for impact” tactics, a ransomware operator’s signature move to terrify victims with warnings splashed across the screen.   

According to Picus, this suggests attackers are moving away from loud encryption techniques to stay under the radar, and are no longer locking data immediately but instead silently exfiltrating it for extortion. 

“We forced the adversary to evolve,” said Dr. Süleyman Özarslan, co-founder and VP of Picus Labs. “As organisations mastered backups and resilience, the traditional business model collapsed. Attackers no longer need to lock your data to monetise it, they just need to steal it. This is why we see a 38% drop in encryption and a staggering 80% surge in evasion techniques.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data