Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Windows Attack Bypasses EDR with Process Injection

New Windows Attack Bypasses EDR with Process Injection

Posted on September 27, 2026 By CWS

A novel Windows process injection technique, revealed by security researcher Two Seven One Three, successfully bypasses traditional EDR monitoring tools. This method cleverly avoids using the typical VirtualAllocEx and WriteProcessMemory APIs known for remote code injection activities.

Innovative Process Injection Method

Named console named-pipe injection, this technique cleverly utilizes a child console process’s redirected standard input to deliver payloads. By repurposing memory that Windows has already allocated, it sidesteps detection systems reliant on the conventional allocate-write-execute pattern.

Process injection, a method where arbitrary code is executed within another process, disguises potentially harmful activities as legitimate application operations. The MITRE ATT&CK framework categorizes this behavior as T1055, highlighting its commonality in cybersecurity incidents.

Mechanics of the Technique

Instead of direct cross-process memory writing, this approach leverages Windows interprocess communication. The injector initiates an interactive console child process, such as nslookup.exe, redirects its standard input to a named pipe, and transmits the payload using WriteFile.

According to Microsoft, a parent process can configure a pipe’s read end as a child’s standard-input handle, retaining the write end. This setup allows the payload to reside in the console program’s address space, where it processes input. The method includes prefixing the payload with a unique marker to locate it in memory and calculating the entry point for execution.

Security Implications and Recommendations

Security expert Two Seven One Three demonstrated a proof of concept where 368 bytes were located in an nslookup.exe region, transforming its protection status from read-write to executable-read-write. This involved suspending and resuming threads with modified instruction pointers.

To effectively counteract this threat, defenders should shift focus from single-API alerts to a comprehensive behavioral analysis. Key indicators include unusual parent processes launching interactive console binaries, binary-like input writes, memory scanning, and remote VirtualProtectEx transitions.

Security teams are advised to baseline console automation activities and scrutinize rare event combinations. This strategic shift aims to enhance detection capabilities beyond typical process-parameter manipulation.

Ultimately, this research underscores the need for robust detection tools that consider process creation, handle sharing, memory protection, and control flow changes, ensuring a multi-faceted approach to cybersecurity.

Cyber Security News Tags:cyber threat, Cybersecurity, EDR evasion, EDR monitoring, malware techniques, process injection, remote code execution, security research, threat detection, Windows security

Post navigation

Previous Post: Citrix Urges Immediate Update for NetScaler Vulnerabilities

Related Posts

Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups Cyber Security News
Hacker Pleads Guilty For Stealing Supreme Court Documents and Leaking via Instagram Hacker Pleads Guilty For Stealing Supreme Court Documents and Leaking via Instagram Cyber Security News
OWASP CVE Lite CLI: Revolutionizing Vulnerability Scanning OWASP CVE Lite CLI: Revolutionizing Vulnerability Scanning Cyber Security News
Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Cyber Security News
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure Cyber Security News
CERT-In Urges Rapid Patching of Critical Vulnerabilities CERT-In Urges Rapid Patching of Critical Vulnerabilities Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Windows Attack Bypasses EDR with Process Injection
  • Citrix Urges Immediate Update for NetScaler Vulnerabilities
  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Windows Attack Bypasses EDR with Process Injection
  • Citrix Urges Immediate Update for NetScaler Vulnerabilities
  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark