logo

A new shellcode in the wild

ID: 73ac7f3f-66f4-5e5f-aea4-d0df09b8c784

STIX ID: report--73ac7f3f-66f4-5e5f-aea4-d0df09b8c784

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzes a.NET sample that uses the "Frenchy" shellcode—identified by a mutex name like "frenchy_shellcode_{version}"—to perform hollow process injection and load AES-encrypted payloads; the report details resource extraction, environment checks, persistence (AppData Tasks copy, VBS and URL startup), DLL mapping to evade API monitoring, and lists numerous affected malware families and associated MD5 indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.