Cyber security
Why antivirus is not enough against modern malware
The Australian Signals Directorate has warned that cybercriminals use crypters to disguise malware and make it harder for security products to detect. In plain English, a crypter changes how malicious code looks so older signature-based tools may miss it. That is why antivirus is not enough when a Sydney business is relying on one control to protect every laptop, server and Microsoft 365 account.
This does not mean antivirus has no value. It means malware defence has changed. Attackers now try to hide known malware inside new packaging, delay execution, check whether they are being analysed, or run code inside trusted processes. ASD describes crypters as a way to make malware fully undetected, often by altering signatures, packing code, obfuscating commands and using anti-analysis techniques.
For a business owner, the useful question is simple. If a malicious file can be made to look different, what else is watching the endpoint? The answer should include behaviour-based endpoint detection, application control, email filtering, DNS protection, MFA, patching, backup and a support team that investigates alerts quickly. That is the practical security model behind Milnsbridge endpoint protection with SentinelOne EDR and the wider cyber security services we manage for Sydney businesses.
Plain English
What a crypter does
A crypter is a tool that changes the appearance of malware. The payload may still be a familiar remote access trojan, ransomware loader, information stealer or credential theft tool. The packaging around it changes so simple file matching becomes less reliable.
It changes the file fingerprint
Traditional antivirus often checks known signatures. A crypter can alter the wrapper around malware so the file misses an older known pattern.
It hides what the code is doing
Obfuscation makes code harder to read. Security tools and analysts need more than a quick scan to understand the intent.
It delays or changes behaviour
Some malware waits before running, checks the environment, or avoids action when it thinks it is inside a sandbox.
It abuses normal Windows activity
Techniques such as process hollowing can make malicious code appear to run inside a legitimate process.
Business risk
Why this matters for Sydney businesses
Most small and mid-sized businesses do not get attacked because they are famous. They get attacked because the attacker can automate the same campaign across many organisations. A staff member receives a convincing email. A link opens a fake login page. A downloaded file runs quietly. A browser or application has not been patched. A password works somewhere it should not.
Crypters make that chain harder to interrupt if the business only checks whether a file is already known to be bad. Modern defence has to look at what happens next. Does the file spawn PowerShell? Does it attempt to disable security controls? Does it start encrypting files? Does it connect to a strange command server? Does it try to dump credentials? Does it run from a location where business software should not run?
That is where SentinelOne EDR is useful. In a Milnsbridge managed environment, SentinelOne is there to watch endpoint behaviour, flag suspicious activity and support fast response when something looks wrong. It is especially useful against disguised malware because it can focus on behaviour rather than only asking whether the file hash is already known.
SentinelOne is one part of the control set. Milnsbridge also uses tools such as ThreatLocker application control, Check Point Harmony email security, Duo MFA, Fortinet FortiGate management, DNSFilter on Growth and Enhanced plans, N-able N-central monitoring, uSecure awareness training and Cove backup services. Each control handles a different part of the attack path. Together they reduce the chance that one disguised file turns into a business-wide incident.
Layered defence
How Milnsbridge services help reduce the risk
No single product prevents every malware event. A useful cyber program puts controls before, during and after execution. The list below shows how specific Milnsbridge services help when attackers use disguised malware.
- SentinelOne EDR watches endpoint behaviour and helps detect suspicious execution, lateral movement and attempted tampering.
- ThreatLocker application control helps restrict what is allowed to run, so unknown software has less freedom to execute.
- Check Point Harmony email security helps stop malicious attachments and links before they reach staff inboxes.
- Duo MFA makes stolen passwords less useful by requiring a second approval step for protected access.
- Managed FortiGate firewalls help control network access, inspection and perimeter policy across business locations.
- DNSFilter helps block access to known malicious domains on supported plans before a user reaches them.
- N-able N-central monitoring gives the support team endpoint visibility, patch status and operational signals.
- Cove backup and disaster recovery gives the business a recovery path if prevention and detection do not stop damage quickly enough.
- uSecure awareness training helps staff recognise suspicious prompts, attachments and credential requests.
This is why antivirus is not enough as a buying criterion. Ask what happens when a file is new, disguised or delivered through a trusted account. The answer should include prevention, detection, investigation and recovery.
Comparison
Traditional antivirus and managed endpoint security
The difference is the product and the management around it. A tool that no one monitors, tunes or responds to quickly can leave the business exposed even when the licence is active.
| Area | Traditional antivirus only | Milnsbridge managed endpoint security |
|---|---|---|
| Detection method | Often relies heavily on known signatures and reputation. | Uses SentinelOne EDR to watch suspicious behaviour as well as known threats. |
| Unknown applications | May allow software to run unless it is already known as malicious. | ThreatLocker can restrict execution to approved applications and policies. |
| Email delivery | The endpoint may be the first serious checkpoint. | Check Point Harmony adds filtering before a risky attachment or link reaches the user. |
| Credential theft | May not stop a valid password being used elsewhere. | Duo MFA and Microsoft 365 controls help reduce the value of stolen credentials. |
| Response | Alert handling depends on whoever notices the warning. | Milnsbridge monitors, investigates and supports response through Sydney-based IT support. |
| Recovery | Recovery may depend on local files or ad hoc backups. | Cove backup and disaster recovery services support planned recovery when damage occurs. |
Practical steps
What to check in your business now
If this ASD warning sounds technical, the response does not need to be confusing. Start with the basic questions your IT support provider should be able to answer clearly.
Confirm what protects endpoints
Check whether laptops and servers have EDR rather than antivirus alone. Confirm who receives alerts and what happens after a high-risk detection.
Control what is allowed to run
Application control is one of the strongest ways to reduce malware execution. It works best when managed carefully so it does not disrupt staff.
Review email and identity controls
Many malware incidents start with email and stolen passwords. Email security and MFA should be treated as part of endpoint defence.
Test backup recovery
Backups only matter if they restore. Recovery testing should be part of the plan before ransomware or destructive malware appears.
Australian context
Why layered controls matter
6 minutes
Average frequency of cybercrime reports to ASD's ACSC in 2024-25. Source: ASD Annual Cyber Threat Report 2024-2025.
84,700+
Total cybercrime reports made to ASD's ACSC in 2024-25. Source: ASD Annual Cyber Threat Report 2024-2025.
59%
Share of January to June 2025 notified data breaches caused by malicious or criminal attacks. Source: OAIC NDB statistics.
532
Total data breach notifications from January to June 2025. Source: OAIC NDB statistics.
Response model
What good protection looks like
Good endpoint security starts before a file runs. Email filtering should reduce dangerous attachments and links. DNS filtering should stop known malicious destinations where it is included. Application control should limit what software can execute. Patching should close known weaknesses before criminals can use them.
Good endpoint security also assumes something will eventually get through. That is why SentinelOne EDR matters. It helps identify behaviour that looks wrong after execution begins. That may include unusual process activity, attempted tampering, credential access, script abuse or lateral movement. From there, the response process matters. Someone has to triage the alert, contain the device where needed, preserve evidence, clean up the endpoint and check whether the same activity touched other systems.
Milnsbridge wraps those tools in practical managed IT services for Sydney businesses. That means the same team that manages endpoints, Microsoft 365, firewalls, backups and user support can see the operational context. A malware alert is easier to investigate when the team already knows the device, user, site and normal business workflow.
This is where local support matters. If a staff member calls because a laptop warning appeared, response speed changes the outcome. Milnsbridge publishes a 20-second average phone answer time and 87% first-call resolution, with the methodology available on our metrics methodology page. Those numbers matter because malware response depends on software and the speed of the human follow-up.
FAQ
Questions business owners ask
What is a crypter in cyber security
A crypter is a tool used to disguise malware so it is harder for security products and analysts to recognise. It can change the file signature, hide code, delay behaviour or use anti-analysis methods.
Does this mean antivirus is useless
No. Antivirus still helps. Antivirus alone is too narrow for modern threats. Businesses need endpoint detection, application control, email protection, MFA, patching and backup.
How does SentinelOne help with disguised malware
SentinelOne EDR helps by watching endpoint behaviour instead of relying only on known file signatures. That helps identify suspicious actions after a disguised file starts to run.
Can application control stop crypter packed malware
Application control can reduce the chance of unknown or unapproved software running. It is a strong layer when managed carefully with business exceptions and change control.
What should a Sydney business do first
Start by confirming whether your current IT support includes EDR, application control, email filtering, MFA, patch management and tested backup recovery. If any of those are missing, close the gap.
Explore more
Related Milnsbridge services
Endpoint protection
See how Milnsbridge uses SentinelOne EDR to protect business endpoints.
ThreatLocker application control
Restrict what can run and reduce the risk from unknown software.
Email security
Reduce malicious emails, links and attachments before they reach staff.
Managed cyber security
Build layered protection across endpoints, users, identity, network and backup.
Talk to Milnsbridge
Check whether your endpoint protection is keeping up
If your business still relies on antivirus alone, Milnsbridge can review your endpoint protection, email security, MFA, application control and backup posture. Our Sydney-based team backs that with a 20-second average answer time and 87% first-call resolution.
Book a cyber security reviewAbout the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
