⤷ Title: Stealth Shellcode Injection in Linux
════════════════════════
𐀪 Author: LordShen
════════════════════════
ⴵ Time: Wed, 21 May 2025 15:31:01 GMT
════════════════════════
⌗ Tags: #malware_development #shellcode #red_teaming #hacking
════════════════════════
𐀪 Author: LordShen
════════════════════════
ⴵ Time: Wed, 21 May 2025 15:31:01 GMT
════════════════════════
⌗ Tags: #malware_development #shellcode #red_teaming #hacking
Medium
Stealth Shellcode Injection in Linux
In this blog, I’m gonna show you how you can execute your shellcode in linux. Before writing the code, I used a few different syscall that…
⤷ Title: MITRE Technique and Detection Opportunities — NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.
════════════════════════
𐀪 Author: MITRE Doggy
════════════════════════
ⴵ Time: Fri, 23 May 2025 07:42:34 GMT
════════════════════════
⌗ Tags: #mitre #shellcode #srdi #nsi #cybersecurity
════════════════════════
𐀪 Author: MITRE Doggy
════════════════════════
ⴵ Time: Fri, 23 May 2025 07:42:34 GMT
════════════════════════
⌗ Tags: #mitre #shellcode #srdi #nsi #cybersecurity
Medium
MITRE Technique and Detection Opportunities — NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign
Rapid7 uncovered an ongoing malware campaign using trojanized NSIS installers disguised as popular apps to deploy the Winos v4.0 malware…
⤷ Title: Shelly — Serve and Execute ShellCode over the wire
════════════════════════
𐀪 Author: Sayan Ray
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 14:26:33 GMT
════════════════════════
⌗ Tags: #hacking_tools #shellcode #hacking #python #windows
════════════════════════
𐀪 Author: Sayan Ray
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 14:26:33 GMT
════════════════════════
⌗ Tags: #hacking_tools #shellcode #hacking #python #windows
Medium
🐚Shelly — Serve and Execute ShellCode over the wire 🚀
I have always come across circumstances where I have seen AVs or EDR Solutions have flagged a file as malware, if it just contains raw…
⤷ Title: Shellcode Injection Methods for Windows
════════════════════════
𐀪 Author: LordShen
════════════════════════
ⴵ Time: Sat, 07 Jun 2025 21:07:01 GMT
════════════════════════
⌗ Tags: #shellcode_injection #malware #hacking #red_team
════════════════════════
𐀪 Author: LordShen
════════════════════════
ⴵ Time: Sat, 07 Jun 2025 21:07:01 GMT
════════════════════════
⌗ Tags: #shellcode_injection #malware #hacking #red_team
Medium
Shellcode Injection Methods for Windows
There are a lot of ways to executing shellcode but most of blog shows only a few ones. Of course, I’m not gonna explain every method. My…
⤷ Title: Stealthy Code Execution via NtMapViewOfSection + RtlCreateUserThread + Hidden Entry Stub
════════════════════════
𐀪 Author: LordShen
════════════════════════
ⴵ Time: Wed, 18 Jun 2025 11:12:37 GMT
════════════════════════
⌗ Tags: #shellcode #malware #red_team #hacking
════════════════════════
𐀪 Author: LordShen
════════════════════════
ⴵ Time: Wed, 18 Jun 2025 11:12:37 GMT
════════════════════════
⌗ Tags: #shellcode #malware #red_team #hacking
Medium
Stealthy Code Execution via NtMapViewOfSection + RtlCreateUserThread + Hidden Entry Stub
This technique is often used by malware authors and it allows you to store your payload in a section. Before doing every step, I’ll explain…
⤷ Title: ZigStrike: New Zig-Based Shellcode Loader Revolutionizes EDR Evasion with Advanced Injection Techniques
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 00:14:58 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Anti_Sandbox #cybersecurity #EDR Bypass #malware #Offensive Security #Payload Delivery #Process injection #shellcode loader #Zig Language #ZigStrike
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 00:14:58 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Anti_Sandbox #cybersecurity #EDR Bypass #malware #Offensive Security #Payload Delivery #Process injection #shellcode loader #Zig Language #ZigStrike
Penetration Testing Tools
ZigStrike: New Zig-Based Shellcode Loader Revolutionizes EDR Evasion with Advanced Injection Techniques
ZigStrike, a new shellcode loader in Zig, offers advanced injection techniques and anti-sandbox features to bypass EDR, providing stealthy execution via local/remote thread and memory mapping.
⤷ Title: [HITB2024] My First and Last Shellcode Loader
════════════════════════
𐀪 Author: CRUNZEX
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 03:47:49 GMT
════════════════════════
⌗ Tags: #penetration_testing #shellcode #windows
════════════════════════
𐀪 Author: CRUNZEX
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 03:47:49 GMT
════════════════════════
⌗ Tags: #penetration_testing #shellcode #windows
Medium
[HITB2024] My First and Last Shellcode Loader
What is a Shellcode Loader?
⤷ Title: DreamWalkers: New Reflective Shellcode Loader Spoofs Call Stacks & Supports .NET for EDR Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 03:11:10 +0000
════════════════════════
⌗ Tags: #Open Source Tool #.NET #Call Stack Spoofing #cybersecurity #DreamWalkers #EDR Bypass #malware #Position Independent Code #Reflective Loading #Research Project #shellcode loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 03:11:10 +0000
════════════════════════
⌗ Tags: #Open Source Tool #.NET #Call Stack Spoofing #cybersecurity #DreamWalkers #EDR Bypass #malware #Position Independent Code #Reflective Loading #Research Project #shellcode loader
Penetration Testing Tools
DreamWalkers: New Reflective Shellcode Loader Spoofs Call Stacks & Supports .NET for EDR Evasion
DreamWalkers Reflective shellcode loader inspired by MemoryModule and Donut, with advanced call stack spoofing and .NET support. Unlike traditional call stack spoofing, which often fails within reflectively loaded modules due to missing unwind metadata, DreamWalkers…
⤷ Title: Process Injection: Harnessing the Power of Shellcode
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 10:58:05 GMT
════════════════════════
⌗ Tags: #reverse_engineering #process_injection #shellcode #hacking #malware_analysis
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 10:58:05 GMT
════════════════════════
⌗ Tags: #reverse_engineering #process_injection #shellcode #hacking #malware_analysis
Medium
Process Injection: Harnessing the Power of Shellcode
Process injection is an advanced penetration testing technique used by skilled security professionals to stealthily insert malicious code…
⤷ Title: Day 63: Shellcodes
════════════════════════
𐀪 Author: Nile Okomo
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 22:45:09 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #shellcode #shell
════════════════════════
𐀪 Author: Nile Okomo
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 22:45:09 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #shellcode #shell
Medium
Day 63: Shellcodes
And why you should learn them
⤷ Title: ¿Cuál me gusta más? CGOblin o gomulti_loader
════════════════════════
𐀪 Author: Lazyown Redteam
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 07:54:31 GMT
════════════════════════
⌗ Tags: #loader #hacking #micro_c2 #shellcode #multiplatform
════════════════════════
𐀪 Author: Lazyown Redteam
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 07:54:31 GMT
════════════════════════
⌗ Tags: #loader #hacking #micro_c2 #shellcode #multiplatform
Medium
¿Cuál me gusta más? CGOblin o gomulti_loader
Elegir entre gomulti_loader y CGOblin depende del caso de uso, ya que ambos son shellcode loaders desarrollados por LazyOwn RedTeam con…
⤷ Title: The ebird3 Chronicles: When Your Calculator Gets a PhD in Cybercrime (And Why That’s Perfectly…
════════════════════════
𐀪 Author: Lazyown Redteam
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 06:27:19 GMT
════════════════════════
⌗ Tags: #windows #shellcode #hacking #injection #early_bird_apc
════════════════════════
𐀪 Author: Lazyown Redteam
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 06:27:19 GMT
════════════════════════
⌗ Tags: #windows #shellcode #hacking #injection #early_bird_apc
Medium
The ebird3 Chronicles: When Your Calculator Gets a PhD in Cybercrime (And Why That’s Perfectly…
> By: grisun0, White Hat Blogger & Chief Overthinker of Suspiciously Suspended Threads
5 min read · Probably posted at 3 AM because sleep…
5 min read · Probably posted at 3 AM because sleep…
⤷ Title: Process Injection: Harnessing The Power of Shellcode
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
ⴵ Time: Thu, 14 Aug 2025 09:35:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #process_injection #shellcode #shellcode_injection #cybersecurity
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
ⴵ Time: Thu, 14 Aug 2025 09:35:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #process_injection #shellcode #shellcode_injection #cybersecurity
Medium
Process Injection: Harnessing The Power of Shellcode
Process injection is an advanced penetration testing technique used by skilled security professionals to stealthily insert malicious code…
⤷ Title: Donut Demystified: How the Shellcode Generator Runs .NET and PE Payloads In-Memory
════════════════════════
𐀪 Author: 0r
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 16:42:02 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #shellcode #pentesting #reverse_engineering
════════════════════════
𐀪 Author: 0r
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 16:42:02 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #shellcode #pentesting #reverse_engineering
Medium
Donut Demystified: How the Shellcode Generator Runs .NET and PE Payloads In-Memory
A walkthrough of Donut — the open-source tool that converts .NET assemblies and Windows binaries into position-independent shellcode…
⤷ Title: NCSC Exposes Advanced Bootkit: RayInitiator and LINE VIPER Malware Found on Cisco ASA Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ArcaneDoor #Bootkit #Cisco ASA #cybersecurity #LINE VIPER #malware #NCSC #RayInitiator #shellcode loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ArcaneDoor #Bootkit #Cisco ASA #cybersecurity #LINE VIPER #malware #NCSC #RayInitiator #shellcode loader
Daily CyberSecurity
NCSC Exposes Advanced Bootkit: RayInitiator and LINE VIPER Malware Found on Cisco ASA Devices
NCSC exposes RayInitiator, a bootkit for Cisco ASA 5500-X devices without Secure Boot, which deploys the LINE VIPER shellcode loader for persistent and stealthy attacks.
⤷ Title: SHELLSILO: The Tool Translating C Code to Syscall Shellcode for Hackers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 03:00:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Assembly #cybersecurity #red teaming #shellcode #SHELLSILO #Syscall
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 03:00:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Assembly #cybersecurity #red teaming #shellcode #SHELLSILO #Syscall
Information Security News
SHELLSILO: The Tool Translating C Code to Syscall Shellcode for Hackers
SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the process of constructing and utilizing structures, assigning vari…
⤷ Title: Founding: The Next-Gen Loader Generator for Advanced Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
Information Security News
Founding: The Next-Gen Loader Generator for Advanced Evasion
Founding is a tool that processes shellcode in .bin, .exe, or .dll formats, applying advanced obfuscation or encryption techniques to generate stealthy binaries with sophisticated execution method…
⤷ Title: DbgNexum: Shellcode injection using the Windows Debugging API
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:32:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:32:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
Penetration Testing Tools
DbgNexum: Shellcode injection using the Windows Debugging API
DbgNexum is a 2026 PoC that uses Hardware Breakpoints and File Mapping to inject shellcode without standard APIs, making it invisible to most EDRs.
⤷ Title: The Invisible Thread: Inside the Multi-Stage Python Injection Powering VioletRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET CLR Hosting #AMSI Bypass #Cyber Security 2026 #malware analysis #Process Hollowing #Python injection #RAT #shellcode #SonicWall #VioletRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET CLR Hosting #AMSI Bypass #Cyber Security 2026 #malware analysis #Process Hollowing #Python injection #RAT #shellcode #SonicWall #VioletRAT
Information Security News
The Invisible Thread: Inside the Multi-Stage Python Injection Powering VioletRAT
Security vanguards at SonicWall have unmasked a nascent campaign disseminating the VioletRAT malware. This offensive orchestrates a multi-tiered delivery sequence and a sophisticated Python-based …
⤷ Title: Agent Smith: Obfuscating Shellcode via Matrix Transformation(s)
════════════════════════
𐀪 Author: Doob
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 22:15:33 GMT
════════════════════════
⌗ Tags: #shellcode #obfuscation #hacking #mathematics #golang
════════════════════════
𐀪 Author: Doob
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 22:15:33 GMT
════════════════════════
⌗ Tags: #shellcode #obfuscation #hacking #mathematics #golang
Medium
Agent Smith: Obfuscating Shellcode via Matrix Transformation(s)
In this write up, we explore a slightly different approach of obfuscation aside from the tried-and-true — XOR.