Security research detailed a Windows code-injection technique that abuses Portable Executable (PE) sections marked readable, writable, executable, and shared (RWX-S) to place shellcode into another process without relying on common cross-process memory operations such as WriteProcessMemory. The method takes advantage of PE shared sections so that changes made in one process can be reflected in another process loading the same image in the same session, potentially reducing visibility to kernel-observed telemetry sources such as Microsoft-Windows-Threat-Intelligence ETW and ObRegisterCallbacks.
The research said attackers could patch a host binary whose entry point resides inside an RWX-S section, causing shellcode to execute when the remote process loads the binary. Using VirusTotal Retrohunt and YARA to identify candidate files, the author found more than 10,000 unsigned matches overall, including 99 unsigned x64 samples, along with roughly 15 uniquely signed binaries with valid Authenticode signatures, only five of them x64. Microsoft PE format documentation provides the structural context for how such shared sections are defined, while the findings suggest these binaries are uncommon enough to give defenders a relatively high-fidelity detection opportunity despite their offensive value.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A blog post published by Bill Demirkapi described a code-injection technique that abuses RWX-S PE sections to place shellcode into a remote process without direct process-memory operations such as WriteProcessMemory. The article also highlighted the technique's implications for evading common kernel-visible telemetry while noting that loading the host binary remains detectable.
The article states that Microsoft discussed shared sections as a security hole in 2004, providing historical context for abuse of PE shared sections.
Using a second YARA rule and a Python script to download low-detection samples and verify signatures, the author identified about 15 unique binaries with valid Authenticode signatures. Only 5 of those uniquely signed RWX-S binaries were x64.
The author created YARA rules and used VirusTotal Retrohunt to search files submitted over the previous 12 months for PE images with readable, writable, executable, and shared sections. The search found more than 10,000 unsigned matches, including 99 unsigned x64 samples.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.