A newly published Windows process-injection technique, described as console named-pipe injection, places payload bytes into an interactive console child process through its standard-input named pipe rather than using the heavily monitored VirtualAllocEx and WriteProcessMemory APIs. The proof of concept launches a console application, sends bytes through standard input with WriteFile, identifies the resulting in-process buffer, changes its protection using VirtualProtectEx, and redirects a thread to execute the payload.
The technique is presented for authorized red-team and penetration-testing use, with no reported vulnerability, threat actor, malware campaign, or confirmed in-the-wild exploitation. Defenders should assess detections for remote VirtualProtectEx activity and unusual named-pipe read/write behavior involving console processes—particularly commonly abused binaries such as netsh.exe and nslookup.exe—rather than relying solely on alerts for cross-process memory allocation or WriteProcessMemory.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Research described a Windows process-injection proof of concept that writes payload bytes through a console child process's standard-input named pipe, locates the resulting remote-memory buffer, makes it executable with VirtualProtectEx, and redirects a thread to execute it. The technique avoids VirtualAllocEx and WriteProcessMemory and was presented as an EDR-evasion approach; no confirmed malicious exploitation was reported.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.