HomeSecurityWindows Fibers: Exploited by hackers for code execution

Windows Fibers: Exploited by hackers for code execution

Two code execution techniques, Poison Fiber and Phantom Thread, exploit a lesser-known feature of the Windows operating system to hide shellcode and other malware on target systems.

windows fibers

Windows fibers, components of the operating system , are one of the undocumented code execution paths that exists exclusively in user mode – and therefore largely overlooked by Endpoint Detection and Response (EDR). As such, they are easy for hackers to exploit to secretly enter computers and deploy malicious payloads.

According to Daniel Jary, an independent security expert, two new Proof of Concept (PoC) attacks using fibers have been discovered. Jary presented the attacks during a session at the Black Hat Asia conference on Thursday.

See also: How to delete Google Chrome on Windows and Mac

Threads are an alternative approach to the traditional "threads" used by Windows to run code within the operating system or an application, as noted.

Windows fibers, which are embedded in threads, are essentially smaller and lighter versions of traditional threads. They were created during a time when central processing units (CPUs) had a limited number of cores and could only support a limited number of threads. In general, the use of Windows fibers was a mechanism for extending the capabilities of a system by making it easier for developers to divide tasks into single threads and make processes more efficient.

"With the evolution of computers becoming more powerful and having enough memory for gaming, fibers have become almost redundant for most uses," says Jary. "That's why many people haven't heard of them and they seem a bit outdated, but they remain useful for certain legacy applications and for porting programs from other operating systems to Windows. Additionally, some processes still rely on the use of Windows fibers.".

Thus, fibers occupy the controversial position of being both a critical and neglected component of Windows by security teams. To start, Jary points out that traditional detection mechanisms used by EDR platforms and antivirus programs often overlook fibers, making them ideal for hiding and executing malicious code.

“EDR agents closely monitor threads, analyzing syscalls and kernel function calls to perform telemetry that is then sent to a rules engine to extract detections,” says Jary. “However, threads operate exclusively at the user application level and are not visible to kernel data collection processes, meaning their telemetry is not actually recorded by EDR systems.”

There are already several open source techniques that exploit the state of fibers to remain inconspicuous. For example, a 2022 PoC provides a detailed description of a technique for embedding malicious shellcode within a fiber, thereby successfully bypassing the majority of antivirus engines.

Some have developed techniques for hiding the call stack, which allow hackers to hide their malicious action within a thread—specifically, within a fiber—behind another fiber, which is inactive and harmless, thus avoiding detection. This method exploits the property of fibers, where at any given time one fiber is active and another is inactive, to which activation is transferred. This advanced system was integrated into Cobalt Strike's Artefact toolkit in 2022.

Read also: How to play Windows games on your Mac with Whiskey 

Jary began an exploration to see if existing malicious fiber techniques could be improved, resulting in the development of two new PoCs, which were named Phantom Thread and Poison Fiber.

Existing fiber methods have some drawbacks for hackers. In particular, some indicators could be exploited for EDR detection, while malicious activity fails to remain indiscriminate through embedded event-based calls. At the same time, any application of techniques for collecting dormant fibers, for which there are a multitude of methodologies, will eliminate the coverage offered by the call stack.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Phantom Thread represents a revolutionary approach to call stack management, allowing fibers to be camouflaged as threads, removing the ability for memory scans to detect them. By creating a fiber and then processing it to appear as a thread, the call stack traces associated with the fibers are eliminated, thus hiding the fibers from any memory scan.

The second PoC, Poison Fiber, captures running Windows processes, analyzing the threads being used. It then checks to see if any of those threads are embedded with fibers. At this point, it provides the ability to embed your own payload or shellcode into an idle fiber, as Jary points out.

“Only one thread can run on each fiber at a time, so there is always another thread that is idle, sitting somewhere in the stack,” he explains. “Using Poison Fiber, we can embed our code in one of these idle fibers, thus avoiding the need to suspend the thread to inject shellcode, which is a clear indication of malicious action. Because the payload is embedded in an idle fiber, the application starts execution for us, taking the initiative of the process.” This technique also offers the added benefit of being able to allow remote code execution (RCE).

While they remain somewhat obscure, fibers should be on the list of attack vectors for security teams, warns Jary, who has yet to publicly share the advanced features of his PoC or the details of his methods, and argues that it is only a matter of time before others discover ways to overcome the obstacles in existing open-source fiber execution methods.

Windows Fibers

“The alternative technique of using fibers is a valuable tool for hackers, as it allows us to bypass the traditional telemetry that we usually receive through threads,” he explains. “Using fibers is not a method for privilege escalation or a technique for bypassing Access (UAC). However, it makes it easier to send beneficial code in a way that attracts significantly less attention and analysis from the security community. Fibers are relatively simple to implement but more difficult to detect, making them ideal for use in attacks against enterprises.”

See also: Windows 10 KB5036892: Improvements and new features

Jary recommends using mature EDR solutions that are able to undergo continuous testing against evolving technical threats, such as those emerging.

“Discuss with your partners the open source methods being used,” he urges. “Do thorough research to understand the preferences of hackers, what is prevalent in the natural environment, and then share this information with your research team and EDR product developers. This process will help develop more effective defenses and could also make the job of the threat response team easier .”

Source: darkreading.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS