A new technique allows cybercriminals to exploit antivirus software by injecting malicious code directly into the software's processes. This approach makes it easier to avoid detection and breach the security that antivirus software is designed to provide.

This method, analyzed by cybersecurity researcher Two Seven One Three on X (@TwoSevenOneT), involves cloning protected services and compromising cryptographic providers to create a backdoor in the antivirus installation folder, bypassing standard defenses.
This approach exposes a vulnerability in the way antivirus solutions prioritize their own stability. By injecting code into these “unkillable” processes, researchers gain elevated privileges to perform actions such as writing files to restricted directories, while simultaneously avoiding detection.
See also: Psychological Engineering: The Invisible Threat of Cybersecurity
As antivirus programs evolve to address complex threats, such techniques highlight the delicate balance between strong security and operational reliability.
Antivirus abuse and defense bypass
Antivirus software uses multiple strategies to protect its core processes from interference, ensuring uninterrupted protection for users. These programs typically run with SYSTEM level privileges, which gives them broad access to monitor and neutralize system-wide threats.
Process introspection allows the antivirus to carefully scan its own threads for signs of strange behavior, such as unauthorized code injection from external sources. Further protection measures include code integrity checks that verify the authenticity of loaded modules and the use of the Protected Process Light (PPL) feature of Windows. This isolates user-mode processes, preventing tampering even by administrators. In the kernel, antivirus drivers deploy sensors to block changes to detection mechanisms, while self-defense routines automatically restart compromised components or alert about suspicious activity.

Defining which processes qualify for protection is equally meticulous. Developers avoid simplistic checks, such as process names, which attackers could spoof by mimicking file names. Instead, solutions like Bitdefender combine verification of the process's ImagePath, ensuring that the executable is in the correct directory, with restrictions on file entries in installation folders. Digital signatures of loaded DLLs add an extra layer, although attackers can try to bypass these through advanced evasion tactics.
Modifying the Process Environment Block (PEB) or using CreateProcess API handles proves futile, as kernel drivers monitor initialization from the beginning.
See also: Ethical hacking with the help of artificial intelligence
How is antivirus misused?
The cleverness of the technique lies in features operating system, while exploiting less protected auxiliary components. Modern antivirus suites include additional features such as firewalls, VPNs, and user interfaces, each of which runs protected processes with write access to the installation folder. Since direct termination or suspension of these is blocked (except by kernel exploits or tools such as EDR-Freeze), researchers turn to cloning.
By manually exporting and importing registry keys for an antivirus service, such as Bitdefender's BDProtSrv, a duplicate service with identical settings. A system reboot loads this clone into the Services.exe cache, creating a new protected process. Tests with Process Explorer confirm protection via "access denied" errors when attempting to terminate.
The introduction is done by exploiting the Windows Cryptography API, which antivirus processes for encryption and signing. Modifying the HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider to point to a malicious DLL triggers loading at service startup.
To avoid signature checks, the DLL is signed using cloned certificates from legitimate Windows programs, a method detailed in the SpecterOps research.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: 175 malicious npm packages used to collect credentials

The steps include creating the cloned service, modifying the provider, verifying the signature, starting the service, verifying execution , and restoring the registry to avoid instability.
IAmAntimalware: A Tool for Testing and Avoidance
To automate this process, Two Seven One Three developed IAmAntimalware, an open-source tool available on GitHub. It clones services, modifies cryptographic providers or COM objects, imports certificates, and initiates the copy, all with command-line parameters that specify the original service, clone name, certificate file, and DLL path.
In tests with Bitdefender, the tool signed a sample DLL using CertClone, another utility . The DLL, which outputs debug strings and writes a “mark.txt” file to the installation folder, was successfully imported upon execution.
Similar results were obtained with Trend Micro and Avast, although Avast required modifications to target the GUI process for reliability. The implications of this method are profound: malware could embed backdoors into antivirus environments, executing them undetected.
Prevention requires careful monitoring of module loads from strange paths, checking for trusted certificates in the registry, and enforcing PPL alongside behavioral analysis.
As penetration testing evolves, such revelations push antivirus vendors to fortify against their own strengths turning into weaknesses.
