APT40 Shellcode Injection & Defense Evasion

Опубликовано: 17 Май 2026
на канале: Prelude
326
8

For this week's TTP Tuesday we are releasing a new APT40 themed chain that showcases shellcode injection and defense evasion through use of OS native API. The release includes a dozen or new executors, available currently in Sliver agents, so you can avoid dropping into a shell.

This chain starts by injecting shellcode into a target process to launch calc.exe. It then demonstrates a number of new executors, such as registryread, mkdir, and getprivs, that you can mix into your own chains for better stealth.