Call stack spoofing started in the game hacking community on UnknownCheats in 2018. A single JMP [RBX] gadget to spoof a return address.
Eight years later it defeats every layer of EDR call-stack-based detection and is CET shadow stack compatible.
The evolution:
@namazso (2018) – original x64 return address spoofing from the game hacking scene. The foundation everything else built on.
@waldoirc YouMayPasser (2022) – first major extension of namazso’s work, bypassing PE-sieve and Moneta using Gargoyle-style ROP with sleep encryption.
@KlezVirus SilentMoonwalk (2022) – desynchronized stack unwinding using real .pdata RUNTIME_FUNCTION entries to construct synthetic frames. Moonwalk++ (2025) combined stack spoofing with memory self-encryption.
@0xmaz LACUNA Chain (2026) – Ghost Frames defeating userland hooks, kernel callbacks, and ETW-Ti stack collection simultaneously. Zero .pdata modification.
BingusLdr (2026) – CET compatible stack spoofing. The shadow stack problem every previous technique ignored, solved.
Commercial C2 frameworks like Havoc Pro from @infinitycurve have already started integrating CET compatible stack spoofing to bypass top tier EDRs. But vendors like @elasticseclabs are catching on, publishing research on detecting shadow stack mismatches and synthetic frame anomalies.
The arms race continues. From game cheats to defeating enterprise EDRs. The tradecraft is the same. The targets changed.
If you build detections for call stack anomalies, this is the history you need to understand.
https://t.co/cm1WtxP4s5
https://t.co/C4fnpcFbGZ
https://t.co/ljyOoz6Yyd
https://t.co/XCPB26sIGw
https://t.co/JmeuCVEQju
https://t.co/ftmycu3ffh
https://t.co/dBRnz8MBJb
https://t.co/vPUlNACBSW
https://t.co/q6nJLjM1kU
@namazso@waldoirc@KlezVirus@0xmaz
#DetectionEngineering #WindowsInternals #InfoSec
New blog & exploit about CVE-2025-29969 - RCE by Yarin Aharoni @safebreach Labs.
Findings allow:
----
* Checking arbitrary paths existence (unfixed!).
* Writing files remotely (RCE).
----
On ALL Windows & Windows Server computers in the domain!
Repo - https://t.co/Ygs0t775RT
New fav persistence method which works on Win11 25H2: Set the default key's value of HKCU\Software\Classes\CLSID\{18907f3b-9afb-4f87-b764-f9a4e16a21b8}\InprocServer32 to point to a malicious DLL and get shells from multiple programs even before a user logs in.
The flaw allows attackers to gain SYSTEM privileges on Windows Server 2025 via a new NTLM relay attack that bypasses LDAP Channel Binding. PoC available!
#WindowsServer#InfoSec#CVE#NTLM#CyberSecurity
https://t.co/CI4qfGyHrP
Telecom Networks digital #forensics process.
A wide range of custom tools/malware designed for telecom environments.
AuthDoor/ChronosRAT/NoDepDNS
https://t.co/1HjE2TTjNx
SGSN Emulator
https://t.co/3nRqELhKHb
GTPDoor
https://t.co/Ejt55pHzCD
Cordscan
https://t.co/kNiwg7VmZJ
#CVE#Exploit#redteam
CVE ID: CVE-2025-23120
System: Veeam Backup & Replication
Type: RCE
Exploit: Veeam Backup & Replication
12.3.0.310 & All earlier version 12 builds.
More Info: https://t.co/1jATzgant2
Poc: https://t.co/KnZda9yhvV