Tech Engine Australia cybersecurity screen showing modern malware threats to businesses
Cyber Security

Is Antivirus Enough for Your Business? What Modern Malware Can Get Past

No. Antivirus is essential, but it cannot protect your business on its own. Malware can conceal its code, misuse legitimate software or steal account access before it is stopped. Security gaps also develop when devices are unprotected, software is outdated or alerts go unanswered.

Modern antivirus can detect more than known viruses. Many products inspect scripts and analyse behaviour. The problem is assuming that installing one means every threat is covered.

Here is what can get through, what the damage can look like and what your business should check.

Malware that changes its appearance

Antivirus signatures recognise known threats. Attackers can alter or conceal malicious code so a file no longer matches a recognised signature. Packing or encrypting a program’s contents can also make inspection harder before it runs.

This does not make the malware undetectable. Behaviour analysis and other detection methods may still catch it. But signature updates alone cannot cover every method attackers use.

Consider a hypothetical download presented as an update for a business application. The installer looks plausible, but contains concealed malicious code. A scanner that does not recognise the file needs other ways to identify the danger, such as suspicious activity when it executes.

The practical response is to control software installation. Staff should obtain applications through approved channels, and your provider should check whether behaviour monitoring is enabled. Ask which devices, folders or programs have been excluded from inspection and why.

Attacks that misuse legitimate tools

Some attacks use software already installed on a computer. PowerShell, for example, helps administrators manage Windows systems. Attackers can misuse the same tool to execute malicious commands.

Other techniques run malicious components in memory, reducing reliance on a conventional executable file saved to disk. These are often described as “fileless” attacks, although the term covers several techniques and does not mean every stage avoids files.

For example, an employee might encounter a fake verification page instructing them to paste a command into Windows. The employee believes they are completing a check. The command instead launches malicious activity through a legitimate system tool.

Fileless techniques are not invisible to modern protection. Script inspection, memory scanning and behaviour monitoring can help detect them. Your provider should be able to explain which capabilities are active.

Staff also need one specific rule: a website asking them to run a command to prove they are human should be reported, not followed.

Infostealers that take access to business accounts

An infostealer does not need to encrypt your files or crash a computer to cause damage. Its purpose is to collect valuable information quietly.

Microsoft’s May 2025 analysis of Lumma Stealer documented its ability to collect saved browser passwords, session cookies and documents. A device could therefore expose business information without showing the obvious disruption associated with ransomware.

Session cookies deserve attention. They can represent an already authenticated login. Depending on the service and its security controls, an attacker who steals one may be able to reuse that session.

Imagine malware being detected and removed from a finance employee’s laptop after browser credentials have been stolen. The laptop may be clean, but the business still needs to establish whether its email or other accounts were accessed.

Resetting affected credentials, revoking sessions and reviewing account activity may all be necessary. Multi-factor authentication remains important, but it does not justify assuming that an existing session is safe.

Account theft can also happen through phishing without malware being installed. A clean antivirus scan cannot establish that an account has not been compromised.

An alert is only the start of the response

Detection does not tell you the full extent of an incident. A malicious file might have run before it was blocked. Other devices could be affected, or credentials might already have been collected.

Endpoint detection and response, or EDR, adds tools for investigating device activity and containing threats. Depending on the product, responders can trace related processes, examine suspicious activity and isolate an infected device.

There is overlap between EDR and antivirus. Start by asking what your existing protection can do, rather than assuming another licence will solve the problem.

The operational questions are more revealing. If an urgent alert arrives after hours, who receives it? Can that person isolate the computer? Who checks whether an account was compromised?

When comparing managed IT services, establish which response tasks are included and which require separate approval or payment. Automatic blocking is valuable, but it does not remove the need for clear responsibility.

What to put around your antivirus

Effective cyber security services should address the gaps that endpoint software cannot close alone.

Patch the software people actually use. Keep operating systems, browsers and business applications current. An inventory matters because an application omitted from maintenance can remain exposed even when Windows updates are working.

Limit installation and administrator access. Application control restricts unauthorised software execution. Removing unnecessary administrator privileges limits what an ordinary staff account can change. Test restrictions against essential business applications and establish a process for approving exceptions.

Protect accounts separately. Use multi-factor authentication and consider phishing-resistant options where supported. Review access permissions, remove accounts that are no longer needed and investigate suspicious sign-ins.

Prove that recovery works. Protect backups from unauthorised alteration and test restoration. Record what was recovered and how long it took. A completed backup job is not evidence that your business can resume operations within an acceptable time.

Several of these controls form part of the Australian Signals Directorate’s Essential Eight. They address different failure points. Backups help recovery, for example, but cannot undo the theft of confidential files.

Ask your provider to show you device coverage, security exceptions, response responsibilities and the latest recovery test. These give you a clearer basis for decisions than a list of installed products.

Check your protection with Tech Engine Australia

At Tech Engine Australia, we help businesses manage their IT and strengthen cyber security. Whether you need IT support in Brisbane or IT support in Melbourne, talk to our team about your endpoint protection, account security and response arrangements. We’ll help you identify gaps and practical next steps for your business.