New Code Injection Method Compromises Antivirus Security

11 Oct 2025

Cybersecurity researchers have unveiled a new code injection technique that poses a serious risk to antivirus software systems, allowing attackers to create dangerous backdoors. This method exploits antivirus processes, compromising their ability to protect against threats.

Technique and Exploitation

The method, described by cybersecurity expert Two Seven One Three, involves cloning protected services and hijacking cryptographic providers. By injecting malicious code into antivirus processes, attackers can bypass standard defenses, accessing restricted directories undetected. This malicious injection leverages stable antivirus features, such as unkillable and SYSTEM-level privileged processes, to insert harmful DLLs at startup.

  • Two Seven One Three identified service cloning as a key weakness in antivirus systems.
  • IAmAntimalware, an open-source tool, automates service cloning and cryptographic provider modifications.
  • Successful injections have been demonstrated on Bitdefender, Trend Micro, and Avast, evading detection with signed DLLs.

Mitigation and Security Measures

To counter these vulnerabilities, experts recommend closer monitoring of module loads from suspicious paths and auditing trusted certificates and registry providers. Enforcement of Windows Protected Process Light (PPL) and the use of behavioral analytics are suggested strategies to mitigate risks.

  • Security audits and anomaly detection are crucial to preventing unauthorized module loads.
  • PPL enforcement can help maintain process integrity.
  • Behavioral analytics can identify unusual system behavior indicative of code injection.

The discovery reveals the tension between ensuring antivirus protection and reducing attack surfaces. While antivirus features are designed to enhance security, they can be exploited for malicious ends, necessitating ongoing vigilance and adaptation by cybersecurity teams.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7246884
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1656351
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
707681
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
487419
downloads

News and reviews for Desktop Windows

Key PC Games Arriving in 2026 Across Steam

In 2026, PC games, including major and indie releases, will feature prominently on Steam, offering fresh options for North America.

Read more

Windows 11 Adds Native NVMe Driver for Faster SSD Performance

Microsoft introduces native NVMe driver on Windows 11 25H2; users experience SSD speed boosts.

Read more

New Game+ Showcase Highlights Indie Releases and Announcements

The New Game+ Showcase on 2024-01-08 spotlighted new Xbox and PC games, including Atomic Heart 2 and Beautiful Light, fueling gaming excitement.

Read more

Igrosoft Features in UK £5 Deposit Casinos

Igrosoft slot games now available at UK casinos offering £5 minimum deposits. Expect welcome bonuses and popular titles.

Read more

Enhance Windows 11 Taskbar with Windhawk Customizations

Windhawk tool enriches Windows 11 taskbar, adding customization options and themes.

Read more

Windows 11 Enhances Access with PowerToys Command Palette

PowerToys Command Palette streamlines app launching and system commands on Windows 11, enhancing user productivity.

Read more

Humble Bundle Offers 7 PC Games for $13.80, Benefits Charity

Humble Bundle's Decked Out Collection offers 7 PC games for $13.80 with proceeds going to the American Cancer Society.

Read more

Affordable Antivirus Options for Home Devices

Discover budget-friendly antivirus deals under $30 for 2026 with essential security features.

Read more

Free Script Removes AI Features from Windows 11

A new script disables AI features like Copilot in Windows 11, offering a cleaner interface.

Read more

Spot Fake BSOD: New Threat Hits Hospitality Sector

A social engineering scam uses a Fake BSOD to target European hotels, tricking staff into installing malware via a browser tab.

Read more