ELF Section Docking: Revisiting Stageless Payload Delivery

When it comes to generating and delivering malware on Linux, offensive operators have choices. Some objectives call for a dynamic payload bootstrap off the wire, others require stageless implants. Often, malware deployed with bundled payloads can be successfully detected and analyzed. However, we think there are opportunities to improve on the process of embedding payloads in standalone implants that can elevate their survival talk will address developments in the static payload embedding and loading. In our discussion, we will revisit the mechanisms of construction of ELF binaries, and will focus on how ELF sections can be used to facilitate a successful payload hosting, retrieval and loading... By: Dimitry Snezhkov Full Abstract & Presentation Materials: #elf-section-docking-revisiting-stageless-payload-delivery-27032
Back to Top