Hacking

Experts devised the GhostHook Attack technique to bypass Windows 10 PatchGuard Protections

Experts have devised the GhostHook Attack technique to install rootkits on machines running the Windows 10 operating system.

Security flaws in Microsoft PatchGuard kernel protection could be exploited by attackers to install rootkits on machines running the secure Windows 10 operating system.

The PatchGuard, also known as Kernel Patch Protection, is a software protection utility that been designed to forbid the kernel of 64-bit versions of Windows OS from being patched in order to prevent rootkit infections or the execution of malicious code at the kernel level.

The security experts at CyberArk Labs have devised a new attack technique dubbed GhostHook attack that bypasses Windows 10 PatchGuard protections.

The GhostHook ,attack is a new hooking technique that requires a hacker to have already compromised a system and running code in the kernel.  This implies that hackers took over the system first using a hacking exploit or delivering a malware.

“this is neither an elevation nor an exploitation technique. This technique is intended for post-exploitation scenario where the attacker has control over the asset. Since malicious kernel code (rootkits) often seeks to establish persistence in unfriendly territory, stealth technology plays a fundamental role.” states the analysis published by CyberArk Labs.

Once a system is compromised, the attackers can implant a rootkit in its kernel that is totally transparent to security solutions, including the PatchGuard.

In a second stage of the attack, the GhostHook attack set up a permanent, secret presence on a compromised machine running 64-bit Windows 10 OS.

According to the researchers at CyberArk, the problem could be very difficult to patch, because the GhostHook attack leverages the technique to gain control of critical kernel structures.

GhostHook attack bypasses PatchGuard by exploiting a weakness in Microsoft’s implementation of a feature in Intel processors called Intel PT (Processor Trace).

The Intel PT is an extension of Intel Architecture that captures information about software execution using dedicated hardware facilities that cause have no impact on the software being traced.

The Intel PT enables security vendors to monitor and trace commands that are executed in the CPU allowing the identification of malicious exploits and malware.

“So basically, Intel PT provides low overhead hardware that executes tracing on each hardware thread using dedicated hardware (implemented entirely in hardware) in the CPU’s Performance Monitoring Unit (PMU). Intel PT can trace any software the CPU runs including hypervisors (except for SGX secure containers).” states the analysis published by CyberArk.“This technology is primarily used for performance monitoring, diagnostic code coverage, debugging, fuzzing, malware analysis and exploit detection.”

Researchers have found a way to abuse the Intel PT technology, the hackers can take advantage of the “buffer-is-going-full notification mechanism” to take control of the execution of the thread.

“How can we achieve that with Intel PT? Allocate an extremely small buffer for the CPU’s PT packets,” continues the analysis. “This way, the CPU will quickly run out of buffer space and will jump the PMI handler. The PMI handler is a piece of code controlled by us and will perform the ‘hook.'”

Another worrisome aspect of the GhostHook attack is that Microsoft downplayed it and it will not issue any emergency patch, but it may address the issue only in a future version of Windows.

“The engineering team has finished their analysis of this report and determined that it requires the attacker already be running kernel code on the system,” said a Microsoft’s spokesperson. “As such, this does not meet the bar for servicing in a security update however it may be addressed in a future version of Windows. As such I have closed this case.” reads the Microsoft’s response to the report.

“This technique requires that an attacker has already fully compromised the targeted system. We encourage our customers to practice good computing habits online, including exercising caution when clicking on links to web pages, opening unknown files, or accepting file transfers.”

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – PatchGuard, GhostHook attack)

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Pwn2Own Berlin 2025 Day Two: researcher earned 150K hacking VMware ESXi

On day two of Pwn2Own Berlin 2025, participants earned $435,000 for demonstrating zero-day in SharePoint,…

10 hours ago

New botnet HTTPBot targets gaming and tech industries with surgical attacks

New botnet HTTPBot is targeting China's gaming, tech, and education sectors, cybersecurity researchers warn. NSFOCUS …

11 hours ago

Meta plans to train AI on EU user data from May 27 without consent

Meta plans to train AI on EU user data from May 27 without consent; privacy…

20 hours ago

AI in the Cloud: The Rising Tide of Security and Privacy Risks

Over half of firms adopted AI in 2024, but cloud tools like Azure OpenAI raise…

22 hours ago

Google fixed a Chrome vulnerability that could lead to full account takeover

Google released emergency security updates to fix a Chrome vulnerability that could lead to full…

23 hours ago

Nova Scotia Power discloses data breach after March security incident

Nova Scotia Power confirmed a data breach involving the theft of sensitive customer data after…

1 day ago