Kaspersky detailed a Windows design flaw that allowed attackers to achieve boot-time kernel shellcode persistence on fully updated Windows 7 and Windows Server 2008 R2 by abusing insecure handling of registry data in legacy graphics drivers. The issue stems from use of RtlQueryRegistryValues with RTL_QUERY_REGISTRY_DIRECT and weak type validation, letting oversized REG_BINARY or REG_SZ values trigger stack buffer overflows where REG_DWORD data was expected in drivers including dxgmms1.sys and dxgkrnl.sys. Kaspersky said the weakness was tied to an incomplete fix for CVE-2010-4398, had been known for years, and was seen in a targeted attack in 2018, while Microsoft did not pursue further remediation because exploitation required administrator privileges.
The attack chain used malicious values under GraphicsDrivers and GraphicsDrivers\MemoryManager to write shellcode to kernel memory at 0xfffff78000000800 and redirect execution there during boot. Kaspersky’s analysis of the recovered payload showed a second stage that injected into vboxtray.exe, loaded a reflective DLL named keylogger.dll, captured keystrokes with a WH_KEYBOARD_LL hook, encrypted the data with RC4 using a key derived from the system MachineGuid, and exfiltrated the logs over UDP port 53. The company published the findings as part of a SAS CTF challenge walkthrough that reconstructed the full intrusion path from registry-based kernel persistence to user-mode keylogging and network exfiltration.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2021-05-13, Kaspersky GReAT published technical details about the Windows kernel API misuse underlying the persistence technique, explaining how insufficient type checking around RtlQueryRegistryValues could lead to stack buffer overflows in legacy drivers such as dxgmms1.sys and dxgkrnl.sys. Kaspersky also said the issue was tied to an incomplete fix for CVE-2010-4398 and that Microsoft declined further remediation because exploitation required administrator privileges.
Kaspersky said the Windows design flaw was observed in a targeted attack in 2018, where malicious registry values enabled persistence and execution of kernel shellcode during boot on Windows 7 and Windows Server 2008 R2. Analysis of the recovered payload showed a second stage that injected into vboxtray.exe, loaded a reflective DLL named keylogger.dll, captured keystrokes, and exfiltrated data over UDP port 53.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.