Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. May 11, 2026: The Red Sun still prevails.

May 11, 2026: The Red Sun still prevails.

Scheduled Pinned Locked Moved Uncategorized
43 Posts 5 Posters 226 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • christopherkunz@chaos.socialC christopherkunz@chaos.social

    May 11, 2026: The Red Sun still prevails.

    However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

    jhr77@mastodon.socialJ This user is from outside of this forum
    jhr77@mastodon.socialJ This user is from outside of this forum
    jhr77@mastodon.social
    wrote last edited by
    #2

    @christopherkunz Possibly the defender then has reached his working temperature...

    christopherkunz@chaos.socialC 1 Reply Last reply
    0
    • jhr77@mastodon.socialJ jhr77@mastodon.social

      @christopherkunz Possibly the defender then has reached his working temperature...

      christopherkunz@chaos.socialC This user is from outside of this forum
      christopherkunz@chaos.socialC This user is from outside of this forum
      christopherkunz@chaos.social
      wrote last edited by
      #3

      @jhr77 I retried later during the day yesterday and it seems that the exploit sometimes gets stuck trying to win the race condition, but generally still works even on a "warm" computer.

      1 Reply Last reply
      0
      • christopherkunz@chaos.socialC christopherkunz@chaos.social

        May 11, 2026: The Red Sun still prevails.

        However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

        jhr77@mastodon.socialJ This user is from outside of this forum
        jhr77@mastodon.socialJ This user is from outside of this forum
        jhr77@mastodon.social
        wrote last edited by
        #4

        @christopherkunz maybe it's linked to system load or a half-working patch from MS...
        It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
        br

        christopherkunz@chaos.socialC wdormann@infosec.exchangeW 2 Replies Last reply
        0
        • jhr77@mastodon.socialJ jhr77@mastodon.social

          @christopherkunz maybe it's linked to system load or a half-working patch from MS...
          It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
          br

          christopherkunz@chaos.socialC This user is from outside of this forum
          christopherkunz@chaos.socialC This user is from outside of this forum
          christopherkunz@chaos.social
          wrote last edited by
          #5

          @jhr77 It works on both, because it's only dependent on Defender and NTFS being available, no physical/hardware constraints as far as I can tell. I suspect it's going away tomorrow, so
          a) try it out today, and
          b) watch the author's Github tomorrow.

          jhr77@mastodon.socialJ 1 Reply Last reply
          0
          • christopherkunz@chaos.socialC christopherkunz@chaos.social

            @jhr77 It works on both, because it's only dependent on Defender and NTFS being available, no physical/hardware constraints as far as I can tell. I suspect it's going away tomorrow, so
            a) try it out today, and
            b) watch the author's Github tomorrow.

            jhr77@mastodon.socialJ This user is from outside of this forum
            jhr77@mastodon.socialJ This user is from outside of this forum
            jhr77@mastodon.social
            wrote last edited by
            #6

            @christopherkunz just installing visual studio....

            christopherkunz@chaos.socialC 1 Reply Last reply
            0
            • jhr77@mastodon.socialJ jhr77@mastodon.social

              @christopherkunz just installing visual studio....

              christopherkunz@chaos.socialC This user is from outside of this forum
              christopherkunz@chaos.socialC This user is from outside of this forum
              christopherkunz@chaos.social
              wrote last edited by
              #7

              @jhr77 I got a great advice from @wdormann - create an example project, delete the main.cpp and paste RedSun stuff. That way, dependencies are already set and you'll have an easier time compiling.

              jhr77@mastodon.socialJ 1 Reply Last reply
              0
              • christopherkunz@chaos.socialC christopherkunz@chaos.social

                May 11, 2026: The Red Sun still prevails.

                However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

                jhr77@mastodon.socialJ This user is from outside of this forum
                jhr77@mastodon.socialJ This user is from outside of this forum
                jhr77@mastodon.social
                wrote last edited by
                #8

                @christopherkunz This is all too simple. Copy.Fail:just execute a python script. RedSun - just compile and run...

                1 Reply Last reply
                0
                • christopherkunz@chaos.socialC christopherkunz@chaos.social

                  @jhr77 I got a great advice from @wdormann - create an example project, delete the main.cpp and paste RedSun stuff. That way, dependencies are already set and you'll have an easier time compiling.

                  jhr77@mastodon.socialJ This user is from outside of this forum
                  jhr77@mastodon.socialJ This user is from outside of this forum
                  jhr77@mastodon.social
                  wrote last edited by
                  #9

                  @christopherkunz @wdormann it worked from the scratch. Just a new project and the cpp file as source. Compile and run...

                  1 Reply Last reply
                  0
                  • jhr77@mastodon.socialJ jhr77@mastodon.social

                    @christopherkunz maybe it's linked to system load or a half-working patch from MS...
                    It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
                    br

                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchange
                    wrote last edited by
                    #10

                    @jhr77 @christopherkunz
                    I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

                    With current definitions, I've not seen RedSun succeed. No matter how long I wait.

                    With old definitions, success is pretty quick.

                    christopherkunz@chaos.socialC buherator@infosec.placeB 2 Replies Last reply
                    0
                    • wdormann@infosec.exchangeW wdormann@infosec.exchange

                      @jhr77 @christopherkunz
                      I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

                      With current definitions, I've not seen RedSun succeed. No matter how long I wait.

                      With old definitions, success is pretty quick.

                      christopherkunz@chaos.socialC This user is from outside of this forum
                      christopherkunz@chaos.socialC This user is from outside of this forum
                      christopherkunz@chaos.social
                      wrote last edited by
                      #11

                      @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

                      Link Preview Image
                      gossithedog@cyberplace.socialG 1 Reply Last reply
                      0
                      • christopherkunz@chaos.socialC christopherkunz@chaos.social

                        @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

                        Link Preview Image
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.social
                        wrote last edited by
                        #12

                        @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                        wdormann@infosec.exchangeW christopherkunz@chaos.socialC 2 Replies Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                          wdormann@infosec.exchangeW This user is from outside of this forum
                          wdormann@infosec.exchangeW This user is from outside of this forum
                          wdormann@infosec.exchange
                          wrote last edited by
                          #13

                          @GossiTheDog @christopherkunz @jhr77
                          Cloud-delivered protection ?
                          If so, then yeah, it's on.
                          It's the same stock Win11 VM that worked in April. Just with Defender updates installed.

                          Link Preview Image
                          christopherkunz@chaos.socialC 1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                            christopherkunz@chaos.socialC This user is from outside of this forum
                            christopherkunz@chaos.socialC This user is from outside of this forum
                            christopherkunz@chaos.social
                            wrote last edited by
                            #14

                            @GossiTheDog @wdormann @jhr77 Yes, cloud protection is on. This is a German Win11 Home, I think. After updating to today's definitions and a reboot, RedSun.exe doesn't seem to win the RC anymore, so the reboot was likely necessary to apply the Defender mitigation.
                            I don't think this is merely a signature update, from what I understood the mitigation requires a core update to Defender.

                            wdormann@infosec.exchangeW 1 Reply Last reply
                            0
                            • christopherkunz@chaos.socialC christopherkunz@chaos.social

                              @GossiTheDog @wdormann @jhr77 Yes, cloud protection is on. This is a German Win11 Home, I think. After updating to today's definitions and a reboot, RedSun.exe doesn't seem to win the RC anymore, so the reboot was likely necessary to apply the Defender mitigation.
                              I don't think this is merely a signature update, from what I understood the mitigation requires a core update to Defender.

                              wdormann@infosec.exchangeW This user is from outside of this forum
                              wdormann@infosec.exchangeW This user is from outside of this forum
                              wdormann@infosec.exchange
                              wrote last edited by
                              #15

                              @christopherkunz @GossiTheDog @jhr77
                              The executable bits for Defender are updated along with sigs.

                              christopherkunz@chaos.socialC 1 Reply Last reply
                              0
                              • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                @christopherkunz @GossiTheDog @jhr77
                                The executable bits for Defender are updated along with sigs.

                                christopherkunz@chaos.socialC This user is from outside of this forum
                                christopherkunz@chaos.socialC This user is from outside of this forum
                                christopherkunz@chaos.social
                                wrote last edited by
                                #16

                                @wdormann @GossiTheDog @jhr77 On second attempt, the exploit worked. So whatever MS did, is still not a 100% mitigation. I''ll try again to reproduce what happened.

                                wdormann@infosec.exchangeW 1 Reply Last reply
                                0
                                • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                  @wdormann @GossiTheDog @jhr77 On second attempt, the exploit worked. So whatever MS did, is still not a 100% mitigation. I''ll try again to reproduce what happened.

                                  wdormann@infosec.exchangeW This user is from outside of this forum
                                  wdormann@infosec.exchangeW This user is from outside of this forum
                                  wdormann@infosec.exchange
                                  wrote last edited by
                                  #17

                                  @christopherkunz @GossiTheDog @jhr77
                                  When it succeeds, does it happen relatively quickly?

                                  I've tried both waiting 10 minutes and have also tried 10 times in a row, and neither strategy is successful on my Win11 VM.

                                  1 Reply Last reply
                                  0
                                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                    @GossiTheDog @christopherkunz @jhr77
                                    Cloud-delivered protection ?
                                    If so, then yeah, it's on.
                                    It's the same stock Win11 VM that worked in April. Just with Defender updates installed.

                                    Link Preview Image
                                    christopherkunz@chaos.socialC This user is from outside of this forum
                                    christopherkunz@chaos.socialC This user is from outside of this forum
                                    christopherkunz@chaos.social
                                    wrote last edited by
                                    #18

                                    @wdormann @GossiTheDog @jhr77 Reboot, log in, win-r, cmd, cd \temp, RedSun.exe, worked on first attempt.
                                    In my last attempt, I had opened the Defender warning popup "defender has found a threat" and I thought I'd triggered some condition for the exploit to work. Seems not, I can still run it.
                                    It succeeds after about 10 seconds.

                                    wdormann@infosec.exchangeW 1 Reply Last reply
                                    0
                                    • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                      @wdormann @GossiTheDog @jhr77 Reboot, log in, win-r, cmd, cd \temp, RedSun.exe, worked on first attempt.
                                      In my last attempt, I had opened the Defender warning popup "defender has found a threat" and I thought I'd triggered some condition for the exploit to work. Seems not, I can still run it.
                                      It succeeds after about 10 seconds.

                                      wdormann@infosec.exchangeW This user is from outside of this forum
                                      wdormann@infosec.exchangeW This user is from outside of this forum
                                      wdormann@infosec.exchange
                                      wrote last edited by
                                      #19

                                      @christopherkunz @GossiTheDog @jhr77
                                      The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                                      It's just that at least for me, it never succeeds with updated defs. 🤷‍♂️

                                      Link Preview Image
                                      christopherkunz@chaos.socialC 2 Replies Last reply
                                      0
                                      • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                        @christopherkunz @GossiTheDog @jhr77
                                        The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                                        It's just that at least for me, it never succeeds with updated defs. 🤷‍♂️

                                        Link Preview Image
                                        christopherkunz@chaos.socialC This user is from outside of this forum
                                        christopherkunz@chaos.socialC This user is from outside of this forum
                                        christopherkunz@chaos.social
                                        wrote last edited by
                                        #20

                                        @wdormann @GossiTheDog @jhr77 Yeah, the first dialog is the detection of EICAR, the second one is the admission of defeat. I get both, and a NT_AUTHORITY shell, on running RedSun.exe.
                                        This is weird, but I suspect we're basically arguing against a ticking clock here. Patch day will land soon and with it, undoubtedly a RedSun mitigation. Actually, let me milk this opportunity for a meme.

                                        Link Preview Image
                                        1 Reply Last reply
                                        0
                                        • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                          @christopherkunz @GossiTheDog @jhr77
                                          The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                                          It's just that at least for me, it never succeeds with updated defs. 🤷‍♂️

                                          Link Preview Image
                                          christopherkunz@chaos.socialC This user is from outside of this forum
                                          christopherkunz@chaos.socialC This user is from outside of this forum
                                          christopherkunz@chaos.social
                                          wrote last edited by
                                          #21

                                          @wdormann @GossiTheDog @jhr77 I think my TieringEngineService.exe might be permanently patched/replaced with the RedSun copy and none of the definitions updates have cleaned it up.

                                          wdormann@infosec.exchangeW 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups