logo

New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

ID: 5f90f147-0926-58b6-82c7-8c13b604f837

STIX ID: report--5f90f147-0926-58b6-82c7-8c13b604f837

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-10-20

Date Updated: 2026-04-21

Author: Guru Baran

...
...

DefenderWrite is a proof-of-concept tool that enumerates whitelisted Windows executables and uses process creation plus remote DLL injection to write arbitrary files into antivirus installation folders, enabling potential persistence and scan evasion. The report documents lab tests on Windows 11 with Microsoft Defender and notes similar findings in other AV products, provides usage parameters and automation scripts, and links to the public GitHub repository while emphasizing ethical testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.