IAmAntimalware Tool Bypasses Antivirus Security with Code Injection

14 Oct 2025

The new tool IAmAntimalware, launched by developer Two Seven One Three on 2025-10-11 via GitHub, manipulates popular antivirus software by injecting malicious code into their processes through advanced techniques.

Cloning Techniques and API Manipulation

IAmAntimalware mimics Windows services by cloning them and imitates digital signatures to bypass antivirus self-protection. The tool hijacks the Windows Cryptography API provider registry key at HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider, allowing unapproved DLLs to be injected where trusted modules should be.

The tool requires user input for parameters such as service names and certificate paths, and supports Protected Process Light (PPL) via an optional P flag. Alternative methods include manipulating COM object CLSIDs, but this requires TrustedInstaller privileges.

Certification Cloning and System Impact

IAmAntimalware uses the CertClone tool to replicate valid Windows certificates, making injected modules appear legitimate. This bypasses protections like process introspection and code signing verification, allowing unauthorized file access or command execution in protected directories.

The developer demonstrated the technique on antivirus services like Bitdefender BDProtSrv, with partial success observed in tests with Trend Micro and Avast. Although it requires system access, exposing no zero-day vulnerabilities, the technique highlights potential flaws in antivirus trust models.

Mitigation Measures and Analysis

Security analysts suggest that while the tool showcases weaknesses, it poses a medium severity risk due to the necessary system access. To counteract these threats, monitoring unexplained module loads, enforcing strict certificate trust policies, applying PPL diligently, regularly verifying antivirus integrity, and deploying endpoint detection with behavioral analytics are recommended.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6096443
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1147844
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
447985
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
425549
downloads

News and reviews for Desktop Windows

Pandora Tomorrow Returns to Steam with Uplay

Pandora Tomorrow is back on Steam with a 40% discount and a Uplay requirement.

Read more

IAmAntimalware Tool Bypasses Antivirus Security with Code Injection

IAmAntimalware, released by Two Seven One Three, circumvents antivirus protections using DLL injection and service cloning.

Read more

Pandora Tomorrow Joins Steam's Splinter Cell Legacy Collection

Pandora Tomorrow, Ubisoft's stealth classic, is now on Steam with discounts. It joins the Splinter Cell Legacy Collection amid new Netflix series debut.

Read more

Absolum: Roguelike Game Free Giveaway on Steam

PCGamesN offers free Absolum Steam keys. Enter by 2023-10-17 for a chance to win this roguelike beat 'em up.

Read more

ReactOS Eyes WDDM Support for Modern GPU Compatibility

ReactOS developers aim to implement WDDM, enhancing GPU support as Windows 10 support ends.

Read more

Frostpunk Hits All-Time Low Price with Complete DLC

Frostpunk slashes prices by 89% for GOTY Edition and DLC, boosting accessibility and replayability.

Read more

Phantom Dash Unlocks in Blue Protocol's Terra Resonance

Unlock Phantom Dash in Blue Protocol via Terra Resonance quest. Enhances gameplay by overcoming obstacles in Andra Rest Post area.

Read more

Blue Protocol Integrates Dance for Player Rewards

Blue Protocol introduces dance emotes in mid-city battles for rewards. Engage in dance at social hubs for exclusive benefits.

Read more

Top Co-op Games Bring Multiplayer Fun to PC

Discover the best PC Co-op Games, from indie hits to AAA titles, offering diverse multiplayer experiences.

Read more

Intel XeSS-MFG Boosts Frame Rates in Supported Games

Intel's XeSS-MFG now improves frame rates in existing XeSS 2 games, enhancing performance without extra developer work.

Read more