New Code Injection Method Compromises Antivirus Security

11 Oct 2025

Cybersecurity researchers have unveiled a new code injection technique that poses a serious risk to antivirus software systems, allowing attackers to create dangerous backdoors. This method exploits antivirus processes, compromising their ability to protect against threats.

Technique and Exploitation

The method, described by cybersecurity expert Two Seven One Three, involves cloning protected services and hijacking cryptographic providers. By injecting malicious code into antivirus processes, attackers can bypass standard defenses, accessing restricted directories undetected. This malicious injection leverages stable antivirus features, such as unkillable and SYSTEM-level privileged processes, to insert harmful DLLs at startup.

  • Two Seven One Three identified service cloning as a key weakness in antivirus systems.
  • IAmAntimalware, an open-source tool, automates service cloning and cryptographic provider modifications.
  • Successful injections have been demonstrated on Bitdefender, Trend Micro, and Avast, evading detection with signed DLLs.

Mitigation and Security Measures

To counter these vulnerabilities, experts recommend closer monitoring of module loads from suspicious paths and auditing trusted certificates and registry providers. Enforcement of Windows Protected Process Light (PPL) and the use of behavioral analytics are suggested strategies to mitigate risks.

  • Security audits and anomaly detection are crucial to preventing unauthorized module loads.
  • PPL enforcement can help maintain process integrity.
  • Behavioral analytics can identify unusual system behavior indicative of code injection.

The discovery reveals the tension between ensuring antivirus protection and reducing attack surfaces. While antivirus features are designed to enhance security, they can be exploited for malicious ends, necessitating ongoing vigilance and adaptation by cybersecurity teams.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6348592
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1255130
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
493935
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453116
downloads

News and reviews for Desktop Windows

Breach Wizards Levels Up with Community Expansion

Tactical Breach Wizards embraces a challenging new level pack. Discounted 40% until 2023-11-09. Includes 'less-than-lethal' pyromancer, Bori.

Read more

Stalker 2 Leaving Game Pass on 2025-11-15

Stalker 2 and Frostpunk exit Game Pass on 2025-11-15. Subscribers have limited time to play these titles before they're removed.

Read more

New PC Bang Spotted in Pyongyang With Asus ROG Setup

North Korea's new PC bang has emerged in Pyongyang, featuring Asus ROG gear and AAA games, suggesting limited, elite access.

Read more

Launches: Europa Universalis 5 and Football Manager 26 Expand PC Games Lineup

New PC games launched this week include Europa Universalis 5 and Football Manager 26, adding variety to the market with strategy and sports simulators.

Read more

Five New Steam Games Released: Notable Titles for November 2025

Explore five new Steam games launched in late October 2025, ranging from narrative adventures to twin-stick shooters and trading simulations.

Read more

Mortal Kombat: Legacy Kollection Faces Early Challenges on Steam

Mortal Kombat: Legacy Kollection launched on Steam with issues, including input lag and online problems. Patches are underway to address concerns.

Read more

Arc Raiders Strains Under Surge of Players

Arc Raiders faces login queues and matchmaking issues as concurrent players spike to 337,834.

Read more

Flyoobe Users Alerted to Potential Malware via Fake Site

Flyoobe users advised to avoid fake site amid security risks. Verify downloads from official channels to prevent malware.

Read more

Diablo 2 Update: New Ammo Types Enhance Ranged Combat

Project Diablo 2 Season 12 adds diverse ammo types, enhancing ranged combat with arrows and bolts. Date to be confirmed during November 8 stream.

Read more

Resonance Solstice Faces Mixed Reviews at Launch

Resonance Solstice, a free Steam game, launched with mixed feedback. Player concerns focus on complex currencies and gameplay mechanics.

Read more