logo

Red Teaming in the age of EDR: Evasion of Endpoint Detection Through Malware Virtualisation

ID: af1d1eb5-3e31-5122-af4e-1cceb6378554

STIX ID: report--af1d1eb5-3e31-5122-af4e-1cceb6378554

Feed Name: Fox-IT blog

Threat Score
70/100

Date Published: 2024-09-25

Date Updated: 2026-04-27

...
...

This blog post describes a Fox-IT research project that implements a custom bytecode virtual machine combined with an in-place instruction encryption scheme and a polymorphic mutation engine to execute position-independent payloads entirely in memory. The system supports transpiling C/C++ into bytecode, native API calls, DLL embedding, multi-VM execution to interleave benign events, and payload staging—techniques intended to evade static signatures and dynamic heuristic/EDR detections and reported as effective in red-team/TIBER engagements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.