logo

Sneaky Shellcode: Windows Fibers Offer EDR-Proof Code Execution

ID: 15cec63d-d6c6-5bb7-bb33-b1137c38a916

STIX ID: report--15cec63d-d6c6-5bb7-bb33-b1137c38a916

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-04-18

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Research presented at Black Hat Asia demonstrates that Windows fibers, a little-used user-mode execution mechanism, can be abused by attackers to stealthily execute code and evade EDRs. The researcher described two PoC techniques — Phantom Thread (masquerading fibers as threads to avoid memory scans and callstack detection) and Poison Fiber (injecting payloads into dormant fibers to trigger execution without suspending threads) — which enable stealthy payload delivery and possible remote code execution; no public release or confirmed active exploitation was reported, but the methods raise notable detection and hunting challenges for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.