Security researchers published a proof-of-concept for remote function stomping, a Windows process-injection method that overwrites an existing exported API function inside another process and then runs the injected payload with a remote thread. The demonstration used notepad.exe as the target and selected CallMsgFilterA from user32.dll, resolving the function locally before modifying the remote process with VirtualProtectEx, writing shellcode through WriteProcessMemory, and triggering execution via CreateRemoteThread.
The write-up said the technique depends on the target DLL already being loaded in the remote process and noted that ASLR can affect DLL base addresses across processes. The authors presented the material as educational for malware researchers, red teams, and defenders, but the compiled sample was reportedly flagged as suspicious in an ANY.RUN sandbox, underscoring the detection and abuse potential of the method.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A technical blog post was published demonstrating remote function stomping on Windows, showing how shellcode can overwrite an exported API function in another process and be executed with a remote thread. The example used notepad.exe, user32.dll, CallMsgFilterA, and documented use of VirtualProtectEx, WriteProcessMemory, and CreateRemoteThread.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecocomelonc.github.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.