New Code Injection Method Compromises Antivirus Security

11 Oct 2025

Cybersecurity researchers have unveiled a new code injection technique that poses a serious risk to antivirus software systems, allowing attackers to create dangerous backdoors. This method exploits antivirus processes, compromising their ability to protect against threats.

Technique and Exploitation

The method, described by cybersecurity expert Two Seven One Three, involves cloning protected services and hijacking cryptographic providers. By injecting malicious code into antivirus processes, attackers can bypass standard defenses, accessing restricted directories undetected. This malicious injection leverages stable antivirus features, such as unkillable and SYSTEM-level privileged processes, to insert harmful DLLs at startup.

  • Two Seven One Three identified service cloning as a key weakness in antivirus systems.
  • IAmAntimalware, an open-source tool, automates service cloning and cryptographic provider modifications.
  • Successful injections have been demonstrated on Bitdefender, Trend Micro, and Avast, evading detection with signed DLLs.

Mitigation and Security Measures

To counter these vulnerabilities, experts recommend closer monitoring of module loads from suspicious paths and auditing trusted certificates and registry providers. Enforcement of Windows Protected Process Light (PPL) and the use of behavioral analytics are suggested strategies to mitigate risks.

  • Security audits and anomaly detection are crucial to preventing unauthorized module loads.
  • PPL enforcement can help maintain process integrity.
  • Behavioral analytics can identify unusual system behavior indicative of code injection.

The discovery reveals the tension between ensuring antivirus protection and reducing attack surfaces. While antivirus features are designed to enhance security, they can be exploited for malicious ends, necessitating ongoing vigilance and adaptation by cybersecurity teams.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6430926
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1291422
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
497603
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454390
downloads

News and reviews for Desktop Windows

ESU Enrollment Errors Persist for Windows 10 Users

Windows 10 ESU enrollment issues arise globally; Microsoft addresses by region. Users may upgrade to Windows 11.

Read more

Windows 11 26H1 Test Build Released to Insiders

Microsoft unveils Windows 11 26H1 test build in the Canary channel, focusing on ARM systems with Qualcomm and Nvidia chips.

Read more

HellLetLoose Offers Discount on 50v50 WWII Shooter

HellLetLoose is discounted on Steam. The strategic WWII shooter features 50v50 battles, preparing for its Vietnam sequel arriving next year.

Read more

Boeing to Implement Microsoft Flight Simulator for Pilot Training

Boeing adopts Microsoft Flight Simulator tech for new pilot training in Portugal. Expected to enhance learning and confidence.

Read more

Nilesoft Shell Enhances Windows 11 Context Menu

Nilesoft Shell lets users customize Windows 11 context menus, improving functionality and ease of access.

Read more

Bonaparte: Tactical Mech Combat and Strategy Launched

Bonaparte: A Mechanized Revolution is now available on Steam, launching with a 17% discount until 2023-11-23.

Read more

Battlestar Galactica Deadlock Pulled From All Storefronts

Slitherine will delist Battlestar Galactica Deadlock on November 15. Players can still play if purchased before then. License expiry likely cause.

Read more

Syberia Remastered Faces Mixed Reviews Post-Launch

Syberia Remastered, launched 2025-11-06, gets mixed Steam reviews due to unchanged cutscenes. Fans debate value amid criticism.

Read more

Replays in 2025 Bring Mass Effect's Normandy to NMS

Hello Games reruns 2025 NMS expeditions, adding Normandy SR-1 to spaceship collections.

Read more

Reentry Hits Steam with Space Simulation Challenge

Lyra Creative releases Reentry 1.0, a NASA-inspired space sim, testing players' skills with a meticulous simulation environment.

Read more