The tool modifies /etc/hosts to redirect security update URLs to localhost, preventing the victim from downloading updated detection tools.