#processinjection — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #processinjection, aggregated by home.social.
-
Observed campaign summary:
Initial Access:
• Phishing emails with Excel (.XLAM) attachments
Execution:
• CVE-2018-0802 (EQNEDT32.EXE)
• HTA → mshta.exe
• PowerShell in-memory decoding
Deployment:
• Fileless .NET loader disguised as Microsoft.Win32.TaskScheduler
• Process hollowing into Msbuild.exe
• AES-encrypted C2 packets
• delimited command protocol
• Plugin-based architecture (50+ modules)Capabilities include credential theft, ransomware, DDoS, system control, registry persistence, and remote command execution.
This campaign demonstrates mature modular RAT engineering combined with social engineering entry points.
Blue teamers - which telemetry source provides the strongest signal here?
Follow @technadu for ongoing malware analysis and threat intelligence coverage.
#Infosec #MalwareResearch #ThreatIntel #XWorm #RAT #ProcessInjection #EDR #DFIR #CyberDefense #BlueTeam #TechNadu
-
Observed campaign summary:
Initial Access:
• Phishing emails with Excel (.XLAM) attachments
Execution:
• CVE-2018-0802 (EQNEDT32.EXE)
• HTA → mshta.exe
• PowerShell in-memory decoding
Deployment:
• Fileless .NET loader disguised as Microsoft.Win32.TaskScheduler
• Process hollowing into Msbuild.exe
• AES-encrypted C2 packets
• delimited command protocol
• Plugin-based architecture (50+ modules)Capabilities include credential theft, ransomware, DDoS, system control, registry persistence, and remote command execution.
This campaign demonstrates mature modular RAT engineering combined with social engineering entry points.
Blue teamers - which telemetry source provides the strongest signal here?
Follow @technadu for ongoing malware analysis and threat intelligence coverage.
#Infosec #MalwareResearch #ThreatIntel #XWorm #RAT #ProcessInjection #EDR #DFIR #CyberDefense #BlueTeam #TechNadu
-
Observed campaign summary:
Initial Access:
• Phishing emails with Excel (.XLAM) attachments
Execution:
• CVE-2018-0802 (EQNEDT32.EXE)
• HTA → mshta.exe
• PowerShell in-memory decoding
Deployment:
• Fileless .NET loader disguised as Microsoft.Win32.TaskScheduler
• Process hollowing into Msbuild.exe
• AES-encrypted C2 packets
• delimited command protocol
• Plugin-based architecture (50+ modules)Capabilities include credential theft, ransomware, DDoS, system control, registry persistence, and remote command execution.
This campaign demonstrates mature modular RAT engineering combined with social engineering entry points.
Blue teamers - which telemetry source provides the strongest signal here?
Follow @technadu for ongoing malware analysis and threat intelligence coverage.
#Infosec #MalwareResearch #ThreatIntel #XWorm #RAT #ProcessInjection #EDR #DFIR #CyberDefense #BlueTeam #TechNadu
-
Observed campaign summary:
Initial Access:
• Phishing emails with Excel (.XLAM) attachments
Execution:
• CVE-2018-0802 (EQNEDT32.EXE)
• HTA → mshta.exe
• PowerShell in-memory decoding
Deployment:
• Fileless .NET loader disguised as Microsoft.Win32.TaskScheduler
• Process hollowing into Msbuild.exe
• AES-encrypted C2 packets
• delimited command protocol
• Plugin-based architecture (50+ modules)Capabilities include credential theft, ransomware, DDoS, system control, registry persistence, and remote command execution.
This campaign demonstrates mature modular RAT engineering combined with social engineering entry points.
Blue teamers - which telemetry source provides the strongest signal here?
Follow @technadu for ongoing malware analysis and threat intelligence coverage.
#Infosec #MalwareResearch #ThreatIntel #XWorm #RAT #ProcessInjection #EDR #DFIR #CyberDefense #BlueTeam #TechNadu
-
It's been quite a bit since I have been on here. A small update:
- I have a security analyst working with me, the help has been great!
- I going back to Penn State for the third time to do a security talk about process injection!
- I am prepping our annual penetration tests against our web app!I continue to grow and learn more about my field in Security and am so grateful for the fun I get to have!
#security #updates #gratitude #processinjection #pennstate -
Well, isn't this just "punch you in the gut while I rip your teeth out" peachy. Never thought a #PoolParty would be such a downer #Hacking #ProcessInjection
https://securityaffairs.com/155464/hacking/pool-party-bypassing-edr.html
-
A couple of blog posts for learning about Linux process injection (specifically sshd injection for credential harvesting)
https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/
-
Memory scanning leaves attackers nowhere to hide – Source: news.sophos.com https://ciso2ciso.com/memory-scanning-leaves-attackers-nowhere-to-hide-source-news-sophos-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #processinjection #filelessmalware #memoryscanning #ThreatResearch #nakedsecurity #nakedsecurity #SophosXOps #FEATURED #featured
-
Memory scanning leaves attackers nowhere to hide – Source: news.sophos.com https://ciso2ciso.com/memory-scanning-leaves-attackers-nowhere-to-hide-source-news-sophos-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #processinjection #filelessmalware #memoryscanning #ThreatResearch #nakedsecurity #nakedsecurity #SophosXOps #FEATURED #featured
-
A couple of quick blog posts for learning about Linux process injection
(specifically sshd injection for credential harvesting)https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/
-
Introduction to Process Hollowing, including how to detect it: https://www.trustedsec.com/blog/the-nightmare-of-proc-hollows-exe/
-
A couple of nice blog posts for learning about Linux process injection
(specifically sshd injection for credential harvesting)https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/
https://jm33.me/sshd-injection-and-password-harvesting.html
#sshd #processinjection #redteam #infosec #cybersecurity #Linux
-
A couple of nice blog posts for learning about Linux process injection
(specifically sshd injection for credential harvesting)https://blog.xpnsec.com/linux-process-injection-aka-injecting-into-sshd-for-fun/
https://jm33.me/sshd-injection-and-password-harvesting.html#sshd #processinjection #redteam #infosec #cybersecurity #Linux