Sneaky Shellcode: Windows Fibers Offer EDR-Proof Code Execution
ID: 15cec63d-d6c6-5bb7-bb33-b1137c38a916
STIX ID: report--15cec63d-d6c6-5bb7-bb33-b1137c38a916
Feed Name: Dark Reading
Date Published: 2024-04-18
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Research presented at Black Hat Asia demonstrates that Windows fibers, a little-used user-mode execution mechanism, can be abused by attackers to stealthily execute code and evade EDRs. The researcher described two PoC techniques — Phantom Thread (masquerading fibers as threads to avoid memory scans and callstack detection) and Poison Fiber (injecting payloads into dormant fibers to trigger execution without suspending threads) — which enable stealthy payload delivery and possible remote code execution; no public release or confirmed active exploitation was reported, but the methods raise notable detection and hunting challenges for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
