Contents

Windows Defender Dies to a One-Click Script While Defender Bypasses Sell for $30 a File

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 
Contents

Windows Defender Dies to a One-Click Script While Defender Bypasses Sell for $30 a File

A script created an account on a fully secured Windows 11 machine, killed the antivirus Windows says cannot be killed, and ran a payload. It needed one click. Its memory had no write protection. ๐Ÿง

The machine had everything switched on. Secure Boot, driver signature enforcement, PatchGuard, Virtualization-based Security, Hypervisor-Enforced Code Integrity. Those are the protections Microsoft built specifically so that an attacker who already has administrator rights still cannot reach the core of Windows. All of them held. The memory did not.

Five researchers presented this at the USENIX Security Symposium in Baltimore on August 13, and walked away with a Distinguished Paper Award. The paper is called Download More RAM: Dismantling Windows Operating System Defences with Mischievous Memory, by Sam Collins, Tom Chothia, William Burgess and Marius Muench of the University of Birmingham, with David Oswald of Durham University.

The script rewrites a chip on the memory module. It creates a new local account, installs a startup script for that account, sets it to log in automatically, and reboots. After the reboot the startup script kills the antivirus and runs a payload. From the first click, no user touches it again.

To get there it had to defeat a Windows defence that is supposed to be absolute. Windows keeps a blocklist of drivers with known holes in them, because loading one of those is a standard way into the kernel. The researchers took a driver from that list and changed four bytes: the checksum field in its PE header. That changes the file’s hash, so the blocklist no longer recognises it, while the digital signature stays valid. Four bytes give more than four billion variants to work through.

A memory module carries a small chip called Serial Presence Detect. When a machine powers on, the motherboard firmware reads that chip to find out what the module is: how much capacity it holds, what its layout looks like, what speed it runs at. The SPD chip is how the memory introduces itself to the computer, and the computer believes what it reads there.

On several consumer DDR4 and DDR5 modules, that chip has no write protection at all. Software with administrator rights can rewrite it.

The researchers rewrote it so the machine reported twice the memory that is physically installed. That extra capacity does not exist. Two different physical addresses end up pointing at the same DRAM cells. Memory that the secure kernel believes it alone can reach becomes reachable through a second address that nothing is watching.

From there they had arbitrary read and write access into memory the operating system had promised was isolated. They patched skci.dll, the library that checks drivers before they load, and switched off the revocation checks. Hundreds of blocked drivers became loadable again. Virtualization-based Security enclaves fell. Hypervisor-Enforced Code Integrity fell. Antivirus and EDR software could be disabled, kernel-level anti-cheat was bypassed, and so was the corporate device management that stops an employee from turning security off.

The case never had to be opened and no hardware was added.

Whether your machine is affected comes down to which memory is in it. The researchers tested eleven consumer modules across DDR4 and DDR5. Three vendors ship at least one product line with the SPD chip completely unprotected: Corsair Vengeance in both DDR4 and DDR5, G.Skill Aegis, and ADATA XPG. Crucial, Kingston, HyperX, G.Skill Trident Z Royal and G.Skill Trident Z NEO carry partial write protection, and partial is enough to stop the attack.

On how widespread that is, the paper is more careful than the reporting on it. Corsair held 17.4 percent of the total memory market in 2025, and the authors cite estimates of 55 percent in the high-performance segment and 72 percent in gaming. ADATA sits at roughly 5 percent of the total market. For G.Skill they could find no reliable figures at all. Their own survey was not exhaustive, so other product lines may carry the same unprotected chip.

Memory aliasing itself is not new, and the paper says so. It builds on BadRAM, presented at the IEEE Symposium on Security and Privacy in 2025 by Jesse De Meulemeester, Luca Wilke, David Oswald, Thomas Eisenbarth, Ingrid Verbauwhede and Jo Van Bulck. BadRAM broke AMD SEV-SNP, and it worked by physically pulling the DIMM out of the machine, taking off the write protection by hand, rewriting the SPD contents and putting the module back.

The BadRAM team noticed at the time that they had come across an unlocked module, and wrote that a software-only version might be possible. They did not build one. The Download More RAM authors put it plainly in a footnote: past work speculated that software-only attacks might be possible, but did not demonstrate them end to end in practice.

David Oswald is an author on BadRAM and on this paper. What his own team wrote down as a possibility in 2025 arrived as a working attack in 2026, and the need for physical access went with it.

The official record reads differently to the award. The issue is tracked as CVE-2026-23670, a Windows Virtualization-Based Security (VBS) Enclave security feature bypass, published on April 14, 2026. The base score is 5.7, which on the CVSS scale is Medium. Microsoft runs its own separate severity labels and rates it Important. The base vector is:

1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

That AC:H and PR:H is the score weighing heavily on the fact that an attacker needs administrator rights before any of this starts. Microsoft’s own entry adds E:U, exploit code maturity unproven, and NVD lists the exploitation status as none.

During the attack, half the memory the machine believes it has does not exist, which normally makes Windows fall over. The researchers kept it stable using the Secure Boot compatible removememory boot configuration setting to reserve the aliased region. Microsoft’s April fix blocks that specific mechanism. It does not put write protection on the SPD chip, because Microsoft does not make the memory. Systems with Secure Boot enabled are protected against the demonstrated chain. Systems without it are not, and other ways of keeping an aliased machine stable are not ruled out by that patch.

That is the layer that switches the scanner off. On the same day, a second piece of research described the layer above it, where you simply pay for the scanner not to see your file.

Insikt Group, the research arm of Recorded Future, published an analysis of 24 threat actors selling crypting services. A crypter takes a working piece of malware and rewrites its packaging so that scanners no longer recognise the file. The code inside does exactly what it did before. What changes is what a scanner sees when it looks at the bytes on disk.

Crypting has been around for years. What changed is that it became a subscription, and the prices are public:

  • โ†’ $30 for a single file at the cheap end
  • โ†’ $39 to $149 a month, or $499 for lifetime access
  • โ†’ $500 a week for one of the two longest-running sellers
  • โ†’ $2,500 a month for a shared plan, $6,000 a month for a private one
  • โ†’ $12,000 and $20,000 for premium packages

Several of these operations are old. One has been trading since 2009, another since 2016. Insikt Group ranked three of the 24 by reputation and history, two at the top tier and one below it, and listed the remaining 21 in an appendix.

The service does not stop at delivery. When detection catches up with a customer’s payload, it goes back to the seller and comes out clean again, with a 24 to 48 hour turnaround on shared plans and 24 hours on private ones. Higher packages promise near instant re-crypting.

The sharpest number in the report is one a seller put there himself. In a sales post from June 2023, mrlapis published before and after scans of a Remcos RAT sample. Before crypting, avcheck.net flagged it 18 times out of 25 engines. After crypting, zero times out of 25.

Insikt Group did not run that test, and it has never been independently verified. This is a seller advertising his own product three years ago, and it has to be read that way. What it does show is what this market sells on, which is not a better payload but a lower number on a scanner.

The same caution applies to the capability lists. These sellers claim to defeat Microsoft Defender, SmartScreen and most of the well-known antivirus and EDR products by name, with AV-kill features, AMSI bypass and syscall unhooking. The report states plainly that those claims should not be treated as verified without sample analysis or detection telemetry behind them. A crypter seller has the same incentive to exaggerate as any other vendor with a price list.

A file that no longer looks like anything still has to do something once it runs. Insikt Group gives the answer defenders have been giving for years. Stop relying on hashes, static signatures and antivirus verdicts, and watch behaviour instead: a process discovering which security products are installed, tampering with them, writing exclusion rules, loading code into memory it did not come with, or naming itself after a legitimate Windows program.

Behavioural detection on Windows leans on Virtualization-based Security, Hypervisor-Enforced Code Integrity and the driver blocklist. Underneath all three sits one assumption, that software holding administrator rights still cannot reach into the secure kernel. That is the assumption Baltimore took apart on the same day.

There is no published research showing these two being used together in an attack. The crypting market is operating right now and has been for years. Download More RAM is academic work with a CVE, a patch and a Distinguished Paper Award, presented two days ago. What connects them is not a shared campaign. The connection is that the recommended defence against the first one runs on the layer the second one takes apart.

What is worth doing:

  • โ†’ Install the April 2026 Windows security updates or later
  • โ†’ Check that Secure Boot is enabled, run msinfo32 and look at the Secure Boot State line
  • โ†’ Corsair memory: iCUE now includes an option to enable write protection on the SPD chip
  • โ†’ Other brands: HWiNFO added the same function, free of charge
  • โ†’ Check the motherboard BIOS or UEFI for an SPD write protection setting
  • โ†’ Crucial, Kingston, HyperX and some G.Skill lines already ship with partial write protection

For the crypting side there is no setting to change, only the habit of reading a clean scan for what it is: information about what a scanner recognised, not a statement about what the file does.

Why a default payload gets flagged the second it lands is something you can watch happen for yourself. So is what changes when an attacker drops no file at all and uses the signed Windows binaries already on the machine. Both are in my ethical hacking course:

โ†’ Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources: Download More RAM (USENIX Security 26) | Malware Crypting Services (Insikt Group) | CVE-2026-23670 (NVD)

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff โ€ข email โ€ข donate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I โ™ฅ open-source and Linux