logo

LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection

ID: cb7e02fb-dc31-5f3a-b264-e50a1369202e

STIX ID: report--cb7e02fb-dc31-5f3a-b264-e50a1369202e

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Divya

...
...

## Executive Summary This report documents the LACUNA Chain "Ghost Frames" technique, which exploits gaps in Windows unwind metadata to construct benign-looking call stacks from trusted DLL addresses (ntdll, kernelbase, win32u, wow64). By chaining these "ghost" frames and exploiting a timing window in ETW-Ti's asynchronous stack collection (the ETW-Ti APC Window), the technique can hide malicious execution from kernel-level stack telemetry and shadow stacks; the study demonstrates successful evasion against multiple enterprise EDRs and recommends detection improvements focused on anomalous gap addresses and multi-telemetry correlation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.