Hackers are leveraging a modified version of the SharpHide tool to create hidden registry values, making to detect and remove.
See also: Hackers used combined vulnerabilities in BeyondTrust and PostgreSQL

This technique leverages Windows registry redirection , making it extremely difficult to detect and remove these hidden persistence mechanisms using conventional tools.
SharpHide is a tool based on a technique documented by eWhiteHatsthat allows the creation of hidden registry keys by adding two zero wide characters (wchar) to the registry path.
Sophos threat analyst Andrew Petruspointed out that this technique effectively hides entries in the Registry Editor, exploiting the inability to handle null characters.
The updated version of SharpHide has been integrated into a PowerShell script, which obfuscates two binary files via Base64 encoding. The first binary contains the malicious payload, while the second acts as a loader, taking responsibility for its execution.
See also: Suspected hacker arrested for attacks in Spain and the US
The loader leverages PowerShell's reflection capabilities, allowing a method that triggers the payload to be dynamically loaded and called via the RegSvcs.exe.

This technique avoids detection by executing the malware inside a legitimate executable.
When run with administrator privileges, the malicious script inserts hidden values into the WOW6432Node, instead of the standard SOFTWARE branch, making it more difficult to detect.
This discrepancy results from registry redirection, a process in which Windows automatically moves registry entries from 32-bit processes to the WOW6432Node branch on 64-bit systems
This makes the hidden values impossible to detect through conventional SharpHide tool deletion methods.
See also: SYZEFXIS Network: Cyberattack causes problems in gov.gr applications
To effectively address this issue, a new tool called SharpDelete. SharpDelete is designed to detect and remove hidden registry values used for access, accurately handling both standard and redirected registry paths.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
