/?pid=19186

Updated:05:26 PM EST Dec 28


this is ggmania.com subsite New code injection method avoids malware detection - TechAmok

New code injection method avoids malware detection - [security]
11:01 AM EST - Dec,07 2017 - post a comment

Presented at Black Hat Europe, a new fileless code injection technique has been detailed by security researchers Eugene Kogan and Tal Liberman. Dubbed Process Doppelganging, commonly available antivirus software is unable to detect processes that have been modified to include malicious code.

The process is very similar to a technique called Process Hollowing, but software companies can already detect and mitigate risks from the older attack method. Process Hollowing occurs when memory of a legitimate program is modified and replaced with user-injected data causing the original process to appear to run normally while executing potentially harmful code.

Unlike the outdated hollowing technique, Process Doppelganging takes advantage of how Windows loads processes into memory. The mechanism that loads programs was originally designed for Windows XP and has changed little since then.

To attempt the exploit, a normal executable is handed to the NTFS transaction and then overwritten by a malicious file. The NTFS transaction is a sandboxed location that returns only a success or failure result preventing partial operations. A piece of memory in the target file is modified. After modification, the NTFS transaction is intentionally failed so that the original file appears to be unmodified. Finally, the Windows process loader is used to invoke the modified section of memory that was never removed


Add your comment (free registrationrequired)

Short overview of recent news articles

Dec,28 2025 NVIDIA Showed Me Their Supercomputer
Dec,28 2025 2026 CPU Launches! AMD, Intel & NVIDIA: Buy Now or Wait?
Dec,27 2025 Disable this Windows Feature that Secretly Eats Up RAM!
Dec,27 2025 New Windows 11 vs Old Malware: Will it survive?
Dec,27 2025 Samsung TriFold Durability Test: We found the limit
Dec,26 2025 TRUST WALLET CONFIRMS SECURITY BREACH
Dec,26 2025 Xiaomi 17 Ultra Leads And Samsung To Follow With A 10 Percent Price
Dec,25 2025 Merry Christmas Gaming Insanity
Dec,24 2025 Battlefield 6 - Official PS5 Features Trailer
Dec,24 2025 NVIDIA GeForce Hotfix Driver 591.67 Released
Dec,23 2025 Finally! A Battery That's Better Than Energizer and Duracell!
Dec,22 2025 NVIDIA Killing Cheap 16GB Local AI GPUs?
Dec,21 2025 Top 10 Movie Sequels of All Time
Dec,21 2025 He Built a Privacy Tool. Now He's Going to Prison (Kone Rodriguez,
Dec,20 2025 Insane Moves! B-Boy Shigekix vs. B-Boy Issin - Red Bull BC One World
Dec,20 2025 9800X3D & RTX 5070 Ti Gaming PC - MSI Project Zero Done Right
Dec,19 2025 The XG27AQWMG Sets a New Standard for 1440p OLED
Dec,19 2025 OnePlus 15R Boasts Huge 7,400 mAh Battery
Dec,19 2025 Motorola Refreshes moto g power for 2026
Dec,18 2025 NVIDIA GeForce 591.59 WHQL Driver
Dec,18 2025 Are We Quitting YouTube Due To DRAM Apocalypse?
Dec,16 2025 The Samsung TriFold is AWESOME!
Dec,16 2025 $30 vs $30,000 TV
Dec,16 2025 Stranger Things 5 - Volume 2 Trailer
Dec,14 2025 Google Brings Live Video Sharing to 911 Calls on Android
Dec,14 2025 Samsung One UI 8.5 Will Offer New Features
Dec,14 2025 Dell AW3225QF Review - 32-inch curved gaming monitor
Dec,13 2025 HW News - AMD Says AI Definitely, Absolutely Not A Bubble, New
Dec,13 2025 The BEST Smartphones of 2025!
Dec,11 2025 10 Atmospheric Games That Might CHANGE YOUR LIFE
Dec,11 2025 Samsung Galaxy S26 Ultra - Samsung Isn't Hiding It Anymore
Dec,10 2025 AMD Releases Adrenalin Edition 25.12.1 WHQL Drivers
Dec,10 2025 S25 Ultra VS 17 Pro Max
Dec,09 2025 All You Need Is Kill - Official Trailer
Dec,09 2025 Why can’t you be NORMAL?!? Roasting Staff Setups
Dec,09 2025 A Ryzen Cooling MONSTER - be quiet Silent Loop 3 Review
Dec,07 2025 The Boys - Official Final Season Trailer
Dec,06 2025 Unemployed in your 30's
Dec,05 2025 Play Store Customers to Receive Automatic Payments from $700 Million
Dec,05 2025 Google's Second Release of Android 16 Brings Smart Notifications
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs