New ‘Early Bird’ Code Injection Technique Discovered

Discussion in 'malware problems & news' started by itman, Apr 14, 2018.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.cyberbit.com/blog/endpoint-security/new-early-bird-code-injection-technique-discovered/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, this was already mentioned in another thread. Quite clever new technique, if I understood it correctly. Especially because it bypasses hooks of security products. I already asked if it's possible for a product like EXE Radar to simply block processes from starting child processes in suspended state, the developer will look into it.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.