Ire identifies another LOTUSLITE specimen
Microsoft Research Brian Caswell, Bob Fleck, Mike Walker, Sarah Smith
Microsoft's Project Ire, an AI agent for malware classification, identified a LOTUSLITE backdoor variant that shared behavioral patterns with known samples but had a different hash not flagged by major security vendors. The sample was detected by only 1 of 72 security vendors on May 28, rising to 7 of 70 by June 4, while CrowdStrike Falcon, SentinelOne, Sophos, and others still missed it. Ire's behavior-based analysis caught the variant through function-by-function reverse engineering without relying on signature matching, demonstrating how agentic analysis can identify malware that escapes traditional detection methods.
Why it matters
Project Ire examined a timely malware sample and determined its intent through reverse engineering—identifying LOTUSLITE characteristics even as most major EDR tools did not detect it. The post Ire identifies another LOTUSLITE specimen appeared first on Microsoft Research.