BYOVD vs User-Space Injection: EDR Evasion Comparison | SROP + process_vm_writev vs Kernel Driver Exploit

BYOVD loads a signed vulnerable driver, exploits it for arbitrary kernel R/W, and terminates EDR at Ring 0 — Windows-only, noisy at driver load time, requires admin. User-space injection (Phantom Evasion Loader) uses SROP frames via sys_rt_sigreturn to fire ptrace without a direct ptrace syscall sequence, writes payload in a single process_vm_writev call (syscall 311), redirects RIP into target process — implant runs inside cron’s address space with cron’s identity. Linux-only. Results: 0/65 VirusTotal static, SROP and process_vm_writev invisible to Hatching Triage behavioral sandbox, only ptrace attach entry detected.

April 29, 2026 · 7 min · JM00NJ
BYOVD vs User-Space Injection: EDR Evasion Comparison | SROP + process_vm_writev vs Kernel Driver Exploit

FUSE Linux Kernel Integer Overflow: pgoff_t Arithmetic Wrap, Maple Tree OOB Write & VMA Corruption

MAX_LFS_FILESIZE only gates the superblock. A poisoned FUSE_GETATTR reply mutates i_size to UINT64_MAX at runtime. The (pos + count - 1) » PAGE_SHIFT arithmetic wraps unsigned, kworker loops become infinite, and vma_merge() degenerates into an arbitrary OOB-write on Maple Tree-backed kernels. Full mm/ subsystem analysis: filemap.c, mmap.c, XArray walk corruption primitives.

April 29, 2026 · 12 min · JM00NJ
FUSE Linux Kernel Integer Overflow: pgoff_t Arithmetic Wrap, Maple Tree OOB Write & VMA Corruption

FUSE Linux Kernel UAF: drop_caches + SIGKILL Race Condition | DirtyCred Use-After-Free & LPE

struct fuse_req holds inode references without bumping i_count. SIGKILL a stalled reader, trigger drop_caches inode eviction, delay fuse_abort_conn — the freed slab slot gets reallocated as struct cred. The race delivers a refcount double-decrement on whatever credential lands there: full DirtyCred-class LPE primitive. Complete race window analysis, SLUB reallocation timing, and RCU lifetime breakdown.

April 29, 2026 · 13 min · JM00NJ
FUSE Linux Kernel UAF: drop_caches + SIGKILL Race Condition | DirtyCred Use-After-Free & LPE

FUSE Trust Boundary Attack: Malicious Daemon i_size Desync → Kernel Heap Overflow via finit_module & kexec

FUSE daemons control filesystem metadata returned to the kernel via vfs_getattr — including i_size. Setting i_size to an inflated value desynchronizes the kernel’s allocation (kmalloc based on reported size) from its ingestion (copy_from_user of actual bytes), creating a heap under-allocation. kernel_read_file() callers — finit_module(2), firmware loader, kexec_file_load(2) — are turned into kmalloc-4k SLUB slab overflow primitives. VFS trust inversion architecture, TOCTOU window analysis, and virtio-fs shared-memory attack surface covered.

April 29, 2026 · 11 min · JM00NJ
FUSE Trust Boundary Attack: Malicious Daemon i_size Desync → Kernel Heap Overflow via finit_module & kexec

Pure Assembly vs C/Rust Malware Evasion: 0/65 VirusTotal, SROP CFG Bypass & Zero Compiler Artifacts

C and Rust binaries carry compiler fingerprints that cannot be removed: GCC function prologues, LLVM unwind tables, CRT startup code, stack canary patterns, .eh_frame sections. Pure assembly has none of these. Empirical test on live x64 C2 implant: 0/65 static detections on VirusTotal, SROP kernel-mediated execution and process_vm_writev (syscall 311) invisible to behavioral sandbox, only entry-phase ptrace caught. CMOV branch-free execution collapses CFG to a single basic block — confirmed effective by SEBD 2019 academic research.

April 25, 2026 · 7 min · JM00NJ
Pure Assembly vs C/Rust Malware Evasion: 0/65 VirusTotal, SROP CFG Bypass & Zero Compiler Artifacts

LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs

LockBit 5.0 Linux encrypts files with ChaCha20+Curve25519 with zero network activity — the public key is embedded at compile time. strace attachment triggers immediate termination. Free space is actively wiped post-encryption to prevent carving. Full analysis pipeline: eBPF syscall tracing, Ghidra static RE of crypto routines, pcap-confirmed network behavior, and extracted IOCs including file markers, dropped ransom note paths, and encryption extension patterns.

April 23, 2026 · 9 min · JM00NJ
LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs
DigitalOcean Referral Badge