Cyber Security

Why Antivirus Is Not Enough Against Modern Malware

in 𝕏
By Adrian Weir | Published 8 September 2026

Cyber security

Why antivirus is not enough against modern malware

The Australian Signals Directorate has warned that cybercriminals use crypters to disguise malware and make it harder for security products to detect. In plain English, a crypter changes how malicious code looks so older signature-based tools may miss it. That is why antivirus is not enough when a Sydney business is relying on one control to protect every laptop, server and Microsoft 365 account.

This does not mean antivirus has no value. It means malware defence has changed. Attackers now try to hide known malware inside new packaging, delay execution, check whether they are being analysed, or run code inside trusted processes. ASD describes crypters as a way to make malware fully undetected, often by altering signatures, packing code, obfuscating commands and using anti-analysis techniques.

For a business owner, the useful question is simple. If a malicious file can be made to look different, what else is watching the endpoint? The answer should include behaviour-based endpoint detection, application control, email filtering, DNS protection, MFA, patching, backup and a support team that investigates alerts quickly. That is the practical security model behind Milnsbridge endpoint protection with SentinelOne EDR and the wider cyber security services we manage for Sydney businesses.

Plain English

What a crypter does

A crypter is a tool that changes the appearance of malware. The payload may still be a familiar remote access trojan, ransomware loader, information stealer or credential theft tool. The packaging around it changes so simple file matching becomes less reliable.

It changes the file fingerprint

Traditional antivirus often checks known signatures. A crypter can alter the wrapper around malware so the file misses an older known pattern.

It hides what the code is doing

Obfuscation makes code harder to read. Security tools and analysts need more than a quick scan to understand the intent.

It delays or changes behaviour

Some malware waits before running, checks the environment, or avoids action when it thinks it is inside a sandbox.

It abuses normal Windows activity

Techniques such as process hollowing can make malicious code appear to run inside a legitimate process.

Business risk

Why this matters for Sydney businesses

Most small and mid-sized businesses do not get attacked because they are famous. They get attacked because the attacker can automate the same campaign across many organisations. A staff member receives a convincing email. A link opens a fake login page. A downloaded file runs quietly. A browser or application has not been patched. A password works somewhere it should not.

Crypters make that chain harder to interrupt if the business only checks whether a file is already known to be bad. Modern defence has to look at what happens next. Does the file spawn PowerShell? Does it attempt to disable security controls? Does it start encrypting files? Does it connect to a strange command server? Does it try to dump credentials? Does it run from a location where business software should not run?

That is where SentinelOne EDR is useful. In a Milnsbridge managed environment, SentinelOne is there to watch endpoint behaviour, flag suspicious activity and support fast response when something looks wrong. It is especially useful against disguised malware because it can focus on behaviour rather than only asking whether the file hash is already known.

SentinelOne is one part of the control set. Milnsbridge also uses tools such as ThreatLocker application control, Check Point Harmony email security, Duo MFA, Fortinet FortiGate management, DNSFilter on Growth and Enhanced plans, N-able N-central monitoring, uSecure awareness training and Cove backup services. Each control handles a different part of the attack path. Together they reduce the chance that one disguised file turns into a business-wide incident.

Layered defence

How Milnsbridge services help reduce the risk

No single product prevents every malware event. A useful cyber program puts controls before, during and after execution. The list below shows how specific Milnsbridge services help when attackers use disguised malware.

  • SentinelOne EDR watches endpoint behaviour and helps detect suspicious execution, lateral movement and attempted tampering.
  • ThreatLocker application control helps restrict what is allowed to run, so unknown software has less freedom to execute.
  • Check Point Harmony email security helps stop malicious attachments and links before they reach staff inboxes.
  • Duo MFA makes stolen passwords less useful by requiring a second approval step for protected access.
  • Managed FortiGate firewalls help control network access, inspection and perimeter policy across business locations.
  • DNSFilter helps block access to known malicious domains on supported plans before a user reaches them.
  • N-able N-central monitoring gives the support team endpoint visibility, patch status and operational signals.
  • Cove backup and disaster recovery gives the business a recovery path if prevention and detection do not stop damage quickly enough.
  • uSecure awareness training helps staff recognise suspicious prompts, attachments and credential requests.

This is why antivirus is not enough as a buying criterion. Ask what happens when a file is new, disguised or delivered through a trusted account. The answer should include prevention, detection, investigation and recovery.

Comparison

Traditional antivirus and managed endpoint security

The difference is the product and the management around it. A tool that no one monitors, tunes or responds to quickly can leave the business exposed even when the licence is active.

Area Traditional antivirus only Milnsbridge managed endpoint security
Detection method Often relies heavily on known signatures and reputation. Uses SentinelOne EDR to watch suspicious behaviour as well as known threats.
Unknown applications May allow software to run unless it is already known as malicious. ThreatLocker can restrict execution to approved applications and policies.
Email delivery The endpoint may be the first serious checkpoint. Check Point Harmony adds filtering before a risky attachment or link reaches the user.
Credential theft May not stop a valid password being used elsewhere. Duo MFA and Microsoft 365 controls help reduce the value of stolen credentials.
Response Alert handling depends on whoever notices the warning. Milnsbridge monitors, investigates and supports response through Sydney-based IT support.
Recovery Recovery may depend on local files or ad hoc backups. Cove backup and disaster recovery services support planned recovery when damage occurs.

Practical steps

What to check in your business now

If this ASD warning sounds technical, the response does not need to be confusing. Start with the basic questions your IT support provider should be able to answer clearly.

Confirm what protects endpoints

Check whether laptops and servers have EDR rather than antivirus alone. Confirm who receives alerts and what happens after a high-risk detection.

Control what is allowed to run

Application control is one of the strongest ways to reduce malware execution. It works best when managed carefully so it does not disrupt staff.

Review email and identity controls

Many malware incidents start with email and stolen passwords. Email security and MFA should be treated as part of endpoint defence.

Test backup recovery

Backups only matter if they restore. Recovery testing should be part of the plan before ransomware or destructive malware appears.

Australian context

Why layered controls matter

6 minutes

Average frequency of cybercrime reports to ASD's ACSC in 2024-25. Source: ASD Annual Cyber Threat Report 2024-2025.

84,700+

Total cybercrime reports made to ASD's ACSC in 2024-25. Source: ASD Annual Cyber Threat Report 2024-2025.

59%

Share of January to June 2025 notified data breaches caused by malicious or criminal attacks. Source: OAIC NDB statistics.

532

Total data breach notifications from January to June 2025. Source: OAIC NDB statistics.

Response model

What good protection looks like

Good endpoint security starts before a file runs. Email filtering should reduce dangerous attachments and links. DNS filtering should stop known malicious destinations where it is included. Application control should limit what software can execute. Patching should close known weaknesses before criminals can use them.

Good endpoint security also assumes something will eventually get through. That is why SentinelOne EDR matters. It helps identify behaviour that looks wrong after execution begins. That may include unusual process activity, attempted tampering, credential access, script abuse or lateral movement. From there, the response process matters. Someone has to triage the alert, contain the device where needed, preserve evidence, clean up the endpoint and check whether the same activity touched other systems.

Milnsbridge wraps those tools in practical managed IT services for Sydney businesses. That means the same team that manages endpoints, Microsoft 365, firewalls, backups and user support can see the operational context. A malware alert is easier to investigate when the team already knows the device, user, site and normal business workflow.

This is where local support matters. If a staff member calls because a laptop warning appeared, response speed changes the outcome. Milnsbridge publishes a 20-second average phone answer time and 87% first-call resolution, with the methodology available on our metrics methodology page. Those numbers matter because malware response depends on software and the speed of the human follow-up.

FAQ

Questions business owners ask

What is a crypter in cyber security

A crypter is a tool used to disguise malware so it is harder for security products and analysts to recognise. It can change the file signature, hide code, delay behaviour or use anti-analysis methods.

Does this mean antivirus is useless

No. Antivirus still helps. Antivirus alone is too narrow for modern threats. Businesses need endpoint detection, application control, email protection, MFA, patching and backup.

How does SentinelOne help with disguised malware

SentinelOne EDR helps by watching endpoint behaviour instead of relying only on known file signatures. That helps identify suspicious actions after a disguised file starts to run.

Can application control stop crypter packed malware

Application control can reduce the chance of unknown or unapproved software running. It is a strong layer when managed carefully with business exceptions and change control.

What should a Sydney business do first

Start by confirming whether your current IT support includes EDR, application control, email filtering, MFA, patch management and tested backup recovery. If any of those are missing, close the gap.

Explore more

Related Milnsbridge services

Endpoint protection

See how Milnsbridge uses SentinelOne EDR to protect business endpoints.

View endpoint protection

ThreatLocker application control

Restrict what can run and reduce the risk from unknown software.

View ThreatLocker service

Email security

Reduce malicious emails, links and attachments before they reach staff.

View email security

Managed cyber security

Build layered protection across endpoints, users, identity, network and backup.

View cyber security services

Talk to Milnsbridge

Check whether your endpoint protection is keeping up

If your business still relies on antivirus alone, Milnsbridge can review your endpoint protection, email security, MFA, application control and backup posture. Our Sydney-based team backs that with a 20-second average answer time and 87% first-call resolution.

Book a cyber security review

About the Author

Adrian Weir

Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.

Meet the Milnsbridge Team
← Back to Tech News

Need IT Support for Your Business?

Managed IT services for Sydney businesses with 10–200 seats. Unlimited support from $119/seat/month, 20-second average response time.

Talk to a Specialist Book a 30-Minute Call