logo

Understanding Sleep Obfuscation

ID: 25d66718-748b-5516-a3b9-0259beb57388

STIX ID: report--25d66718-748b-5516-a3b9-0259beb57388

Feed Name: Binary Defense Blog

Threat Score
55/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This report analyzes three open-source in-memory sleep-obfuscation techniques (Ekko, Cronos, FOLIAGE), detailing how they encrypt/decrypt memory and use timers/APCs/NtContinue to evade detection, provides results from testing POCs and Havoc C2 payloads, evaluates detection approaches (memory scanners, CFG/POC tools, and Microsoft Defender/Sentinel telemetry), and identifies gaps and potential detection opportunities such as ETW tracing, specific API call logging, and NtContinue monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.