Polymorphic malware automatically changes its code signature on each replication while maintaining its core function, evading signature-based antivirus. Metamorphic malware goes further — rewriting its entire code structure so that each copy is functionally equivalent but structurally completely different, defeating even heuristic detection.
Aspect Polymorphic Metamorphic Mechanism Encrypted payload + variable decryptor Full code rewrite Signature Changes each replication Changes each replication Decryptor Mutated each generation No decryptor (no encryption) Code Structure Same, just encrypted Completely rewritten Detection Difficulty High (signatures fail) Very High (heuristics fail) Complexity Moderate Very High
Milestone Year Details 1260 Virus 1990 First true polymorphic (Mark Washburn) DAME 1992 Dark Avenger Mutation Engine; toolkit Tremor 1993 Polymorphic engine toolkit SMEG 1994 Simulated Metamorphic Encryption Generator W32/Simile 2002 90%+ code change per generation MetaPHOR 2002 Metamorphic engine Virut 2006 Polymorphic file infector + botnet Sality 2003+ Polymorphic file infector + worm
└─ Payload encrypted with variable key
└─ Only decryption stub visible
└─ Rewrite decryption stub differently each replication
└─ Junk instructions, register swapping, instruction substitution
└─ Decryptor runs → decrypts payload → executes payload
└─ Payload infects new files with new mutation
└─ Analyse own code into instruction stream
├─ Instruction substitution (ADD ↔ SUB + NEG)
├─ Register renaming (EAX ↔ EBX)
├─ Instruction reordering (independent blocks)
├─ Dead code insertion (NOP, JMP, junk)
├─ Control flow flattening
└─ Loop unrolling/rolling
└─ Emit functionally equivalent but structurally different code
Malware Year Type Mutation Rate 1260 Virus 1990 Polymorphic First true DAME 1992 Polymorphic Toolkit W32/Simile 2002 Metamorphic 90%+ change Virut 2006 Polymorphic File infector + botnet Sality 2003+ Polymorphic File infector + worm
Method Polymorphic Metamorphic Signatures ❌ Fail ❌ Fail Heuristics ⚠️ Partial ❌ Often fail Emulation ✅ Decrypt in sandbox ⚠️ Timeout risk Behavioural ✅ Runtime behaviour ✅ Runtime behaviour Memory Scanning ✅ Decrypted in memory ✅ Decrypted in memory ML/ML-based ✅ Pattern recognition ✅ Pattern recognition
✅ Heuristic/behavioural detection — Not signatures alone
✅ Sandboxing — Observe in isolation
✅ Application whitelisting — Only known-good executables
✅ Memory scanning — Detect at runtime regardless of disk form
✅ ML-based detection — Train on behavioural patterns
✅ Keep AV updated — Modern engines use multiple methods
Technique ID Description Obfuscated Files T1027 Polymorphic encryption Software Packing T1027.002 Runtime packing Binary Padding T1027.001 Size manipulation