ZeroHour
Schneier on Securitypublished ()ingested

PROPagate Code Injection Seen in the Wild

mediumMalwareimportance 30
Full article123 words · extracted from schneier.com · click to collapse

Last year, researchers wrote about a new Windows code injection technique called PROPagate. Last week, it was first seen in malware:

This technique abuses the SetWindowsSubclass function—a process used to install or update subclass windows running on the system—and can be used to modify the properties of windows running in the same session. This can be used to inject code and drop files while also hiding the fact it has happened, making it a useful, stealthy attack.

It’s likely that the attackers have observed publically available posts on PROPagate in order to recreate the technique for their own malicious ends.

Tags: malware, passwords

Posted on July 9, 2018 at 6:13 AM14 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2018/07/propagate_code_.html