
Thread Execution Hijacking
Created the Saturday 23 March 2019. Updated 2 months, 2 weeks ago.
Thread execution hijacking is a technique used by malware to evade detection by targeting an existing thread of a process and avoiding any noisy process or thread creation operations. This technique allows the malware to run its code within the context of the targeted thread, without creating new processes or threads, which can be easily detected by security software.
During analysis, it is possible to observe calls to CreateToolhelp32Snapshot
and Thread32First
functions followed by OpenThread
, which are used by the malware to enumerate and select the target thread.
Code Snippets
Contributors
Additional Resources
External Links
The resources provided below are associated links that will give you even more detailed information and research on current evasion technique. It is important to note that, while these resources may be helpful, it is important to exercise caution when following external links. As always, be careful when clicking on links from unknown sources, as they may lead to malicious content.