Cymulate researchers disclosed Blindside, a Windows defense-evasion technique that uses hardware breakpoints and debug registers to acquire a clean ntdll.dll image and replace the hooked .text section in a target process. It creates a child process under debugging, breaks on LdrLoadDll to prevent further DLL loading, and copies the child’s clean ntdll memory before user-mode EDR instrumentation can be introduced. Cymulate said the technique bypassed many, but not all, tested EDR and XDR products and that it notified affected vendors.
The research builds on DLL-unhooking approaches that recover ntdll from newly created suspended processes, where the library is mapped before EDR user-mode DLLs may load. Such techniques can locate the module through the PEB, read its clean image from the child process, change target-memory protections, and restore the original .text bytes to remove syscall hooks; Cymulate reported a proof of concept subsequently loaded encrypted calculator shellcode against some products. Defenders should detect anomalous debugging activity, especially SetThreadContext calls and changes to debug registers DR0–DR3, correlated with suspended-child creation, LdrLoadDll breakpoints, cross-process memory reads, and writes to ntdll executable code.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A technique was described that creates a suspended child process to read its initially unhooked ntdll.dll image, then overwrites the current process’s hooked ntdll .text section. The proof of concept reportedly unhooked ntdll and loaded encrypted calculator shellcode against some tested EDR products, while others detected the behavior.
Cymulate stated that it notified vendors whose products were tested and submitted a Blindside report to the Microsoft Security Response Center before publication. Microsoft had declined to comment at the time described by the source.
Cymulate Offensive Research Group described Blindside, which debugs a child process, prevents further DLL loading at LdrLoadDll, and copies its clean ntdll.dll .text section over a target process’s hooked ntdll. Cymulate reported the technique bypassed many, but not all, tested commercial EDR and XDR products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cymulate.com
Open sourcecymulate.com
Open sourceired.team
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.