@biocib I cannot say with 100% certainty that Norton would detect and quarantine that malware. AI says yes.
AI Overview
Norton 360 detects and blocks threats like Okobot malware using real-time behavioral analysis, machine learning, and signature scans. [1, 2]
How Norton Handles Malware
Behavior Tracking: Looks at what a program does (like changing system files or sending data) instead of just checking the file name.
Smart Scans: Runs quick or full system checks to find hidden malicious apps.
Real-Time Block: Stops active threats from running or spreading on your device. [1, 2, 3, 4, 5]
Steps to Clean Your Device
Open App: Launch the Norton 360 software on your computer or phone.
Run Scan: Choose a Full System Scan to search deep into your files.
Remove Threat: Follow the screen prompts to quarantine or delete any dangerous items found. [1, 2, 3, 4]
There are a few user interactions that can get a system infected through whatever system permissions the logged in user has on the web.
One is ClickFix Attacks: Tricks users into typing or running harmful PowerShell commands via fake system error alerts
Another is Trojanized GitHub Software: Distributes fake installers for popular developer tools (like SQL Server Management Studio) bundled with malicious code.
And of course if you have a crypto wallet sitting unsecured that is also a target.