RTV Overflow: "Building Your First Windows Malware Loader"

Опубликовано: 18 Май 2026
на канале: Red Team Village
218
9

Royce Yaezenko, 0xtengu, assistant researcher

Malware analysis often focuses on detonation, leaving new defenders and red‑teamers wondering how a loader is actually assembled. In this accelerated, beginner‑friendly, two‑hour hands‑on workshop, participants start with a ready‑to‑build Visual Studio solution and finish with a fully functional Windows 11 process‑injection loader written in C. We focus on the classic three‑call technique: VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread, plus a quick single‑byte XOR obfuscation pass and file bloating operation. All workshop time is devoted to getting a working loader, testing it against Windows Defender, and understanding each step well enough to particpants can expand beyond it.

___________________________________________________________

The Red Team Village

Red Team Village Website: redteamvillage.io
Discord: redteamvillage.io/discord
Twitter: twitter.com/RedTeamVillage_
Instagram: instagram.com/theredteamvillage
BlueSky: bsky.app/profile/theredteamvillage.bsky.social