HomeSecurityNew Mockingjay process injection technique evades EDR detection

New Mockingjay process injection technique evades EDR detection

A new process injection technique dubbed “Mockingjay” could allow threat actors to bypass EDR (Endpoint Detection and Response) and other security products by secretly executing malicious code on compromised systems.

See also: MOVEit: Hackers steal data of 45,000 New York students

New Mockingjay process injection technique evades EDR detection

Researchers at cybersecurity firm Security Joes have discovered a method that uses legitimate DLLs with RWX (read, write, and execute) sections to evade EDR hooks and inject code into remote processes.

Process Injection is a method of executing arbitrary code in the address space of another running process, which is trusted by the operating system. This gives threat actors the ability to execute malicious code without being detected.

Examples of process injection techniques include DLL injection, PE (portable executable) injection, thread execution hijacking, Process Hollowing, mapping injection, APC (asynchronous procedure call) injection, and others.

See also: Mallox ransomware attacks IT industries with new attack pattern

In all of these techniques, attackers must use Windows APIs and various system calls, create processes/threads, etc. Therefore, security tools that monitor for specific actions related to the above can detect suspicious incidents and intervene as needed.

Joe from Security says that Mockingjay stands out from other approaches because it doesn't frequently use abusive Windows API calls, doesn't set special permissions, doesn't perform memory allocations, or start threads, thus eliminating many potential detection opportunities.

Mockingjay

The researchers' first goal was to find a vulnerable DLL with a default section that was writable, executable, and readable (RWX), so they could modify its contents to load malicious code without performing additional steps like obtaining additional permissions, which could raise red flags in security software.

In their search for a suitable DLL, Security Joes analysts discovered msys-2.0.dll within Visual Studio 2022 Community, which had a default 16 KB section with RWX permissions.

The team then developed two injection methods: one for self-injection and one for remote process injection.

In the first case, a custom application (“nightmare.exe”) loads the vulnerable DLL directly into memory space using two Windows API calls, giving it direct access to the RWX section without performing any memory allocation or setting any permissions.

Mockingjay

Next, a clean system module, NTDLL.DLL, is misused to extract syscall numbers, which are then used to bypass EDR hooks using the “Hell's Gate EDR unhooking” technique, allowing the injected shellcode to execute undetected.

New Mockingjay process injection technique evades EDR detection

The second method involves exploiting the TWX section of msys-2.0.dll to inject a payload into a remote process, specifically the “ssh.exe” process.

The custom application launches ssh.exe as a child process, opens a handle to the target process, and injects malicious code into the RWX memory space of the vulnerable DLL.

Mockingjay

Finally, the imported shellcode loads the DLL file “MyLibrary.dll”, creating a reverse shell on the attacker's machine, as an example of an attack.

Mockingjay

Tests have shown that this remote injection attack, which does not require the creation of a new thread in the target process, memory allocation, or permission setting, successfully evades EDR solutions.

Both methods proposed in Mockingjay use Windows such as "LoadLibraryW", "CreateProcessW", and "GetModuleInformation" to load a misconfigured DLL and find the address of the DLL's RWX module.

However, EDRs typically monitor APIs such as “WriteProcessMemory”, “NtWriteVirtualMemory”, “CreateRemoteThread”, or “NtCreateThreadEx”, which are more commonly called in traditional process injection attacks. Therefore, Mockingjay is less likely to raise alarms.

See also: Increase in cyberattacks on law firms

Joes Security's development of "Mockingjay" is another indication of why organizations need to adopt a holistic approach to security rather than relying solely on current EDR solutions.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS