Sunday 26 July 2026 11:18:40 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Shellcode


Trust as a Trap: The Loader That Turns Signed Windows Paths Into Evasion

Published: 23 July 2026 16:30Category: Cyber Warfare & Nation-State OperationsGeo: Asia / ChinaAuthor: AGONY

TriBack Loader is a reminder that valid signatures and ordinary Windows callback paths can be used as cover, not proof of safety.

Windows Startup Fields Turn Into a Quiet Shellcode Cache

Published: 10 July 2026 12:22Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

Process Parameter Poisoning, or P³, treats ordinary process startup data as a staging area, a move that may blunt the telemetry many defenders expect from conventional injection.

Windows Process Parameter Poisoning Moves Payload Logic Into Plain Sight

Published: 10 July 2026 10:05Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A newly documented process-injection technique places shellcode or DLL-loading logic inside ordinary startup parameters and is designed to avoid some API calls commonly tied to remote process injection.

Windows Explorer Hijack Puts a Hidden PNG in the Driver’s Seat

Published: 08 July 2026 14:48Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A reported intrusion chain combines COM hijacking, image-based concealment, and AES encryption, showing how ordinary Windows features can be bent into a stealth delivery path.

ValleyRAT’s Quiet Upgrade: Encryption, Shellcode, and a Trusted Windows Host

Published: 02 July 2026 12:17Category: Malware & BotnetsGeo: Asia / ChinaAuthor: IRONQUERY

The latest ValleyRAT activity shows a layered Windows tradecraft chain built to stay in memory, reduce disk artifacts, and make routine detection harder for defenders.

Windows Callback Path Turned into a Quiet Code-Routing Trick

Published: 29 June 2026 12:26Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A newly described injection method rides the Win32 callback boundary and may leave the KernelCallbackTable looking normal, forcing defenders to look beyond simple pointer checks.

When a Loader Hides in Plain Sight, the Clipboard Becomes the Target

Published: 19 May 2026 10:22Category: Malware & BotnetsAuthor: SIGNALMONK

A reported CountLoader campaign shows how Windows-native scripts, staged execution, and memory-resident payloads can turn a routine infection path into a theft mechanism aimed at crypto users.