TLDRocket
Sign in

Ire identifies another LOTUSLITE specimen

Microsoft Brian Caswell, Bob Fleck, Mike Walker, Sarah Smith

Microsoft's Project Ire, an AI agent for malware classification, identified a LOTUSLITE backdoor variant that shared behavioral patterns with known samples but had a different hash not flagged by major security vendors. The sample was detected by only 1 of 72 security vendors on May 28, rising to 7 of 70 by June 4, while CrowdStrike Falcon, SentinelOne, Sophos, and others still missed it. Ire's behavior-based analysis caught the variant through function-by-function reverse engineering without relying on signature matching, demonstrating how agentic analysis can identify malware that escapes traditional detection methods.

Why it matters

Project Ire examined a timely malware sample and determined its intent through reverse engineering—identifying LOTUSLITE characteristics even as most major EDR tools did not detect it. The post Ire identifies another LOTUSLITE specimen appeared first on Microsoft Research.

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.