logo

Burrowing a Hollow in a DLL to Hide

ID: e89f80f7-9bdb-5712-8a74-369d6f4820c5

STIX ID: report--e89f80f7-9bdb-5712-8a74-369d6f4820c5

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report documents DLL hollowing — a process-injection technique where a benign DLL is forced into a process and its entry point overwritten with malicious shellcode. It includes multiple proof-of-concept implementations in C and C# (simple in-process and remote process with PPID spoofing), embedded reverse-shell payloads and example C2 IPs, and notes on reversing and detection outcomes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.