DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

Khushal

Level 11
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
516
2,647
969
⚠️ DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

Read more: New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

A new tool called DefenderWrite exploits whitelisted Windows programs to bypass protections and write arbitrary files into antivirus executable folders, potentially enabling malware persistence and evasion.

The core innovation behind DefenderWrite lies in systematically scanning Windows executables to find those permitted to access AV folders.

By identifying system programs that antivirus vendors whitelist for updates and installations, attackers can leverage these exceptions to inject malicious DLLs, turning the AV's own safeguards against it.

Some Antivirus have been successfully tested​

  • Microsoft Windows Defender
  • BitDefender Antivirus
  • TrendMicro Antivirus Plus
  • Avast Antivirus
 
Last edited: