TGViewer
Fsecurity | HH Fsecurity | HH @hellohackingteam · 2.06K subscribers
Post #7767 163

Forwarded from 1N73LL1G3NC3

PhantomCtx

A tool that automates Activation Context hijacking with the objective of loading an arbitrary DLL into the vast majority of signed executables (e.g. Microsoft, Adobe, Mozilla).

The loader is presented as a modern alternative to traditional DLL Hijacking & Sideloading: unlike conventional approaches, it does not require a vulnerable binary. The technique can be performed as long as the target executable resolves a DLL through its Import Address Table (IAT) or, in the worst case, via LoadLibrary without an absolute path.

For a deeper dive into how it works internally and how it evades aggressive EDR solutions, check out the post on my technical blog.
  • 👍 2
More from @hellohackingteam
  1. Oct 8, 2026🔗 Ссылка: https://codeby.net/threads/analiz-kiberintsidentov-v-rossii-2025-proval-signatu…
  2. Oct 8, 2026LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warning…
  3. Oct 8, 2026Чаще всего во время работ по анализу защищённости пробив периметра происходит через выполн…
  4. Oct 7, 2026Sliver GUI — это кроссплатформенное настольное приложение на базе Electron для Sliver. Оно…
  5. Oct 7, 2026🔗 Ссылка: https://fortbridge.co.uk/research/wordpress-libheif-rce/
  6. Oct 7, 2026CVE-2026-43783: Починить права — получить root: LPE через DesktopServicesHelper в macOS 26…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →