<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🎙️ EntryPoint Hijacking introduces a stealthier approach to code injection as it doesn’t use API calls that create a new thread within the context of a process.]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f399.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--studio_microphone" style="height:23px;width:auto;vertical-align:middle" title="🎙" alt="🎙" />️ EntryPoint Hijacking introduces a stealthier approach to code injection as it doesn’t use API calls that create a new thread within the context of a process. </p><p>Arbitrary code is written in memory, but it is executed only when a thread is created by the process legitimately. </p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f6e0.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--hammer_and_wrench" style="height:23px;width:auto;vertical-align:middle" title="🛠" alt="🛠" />️  𝐀 𝐍𝐞𝐰 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧‑𝐅𝐨𝐜𝐮𝐬𝐞𝐝 𝐂𝐚𝐩𝐚𝐛𝐢𝐥𝐢𝐭𝐲<br />In the article, a 𝐭𝐨𝐨𝐥 is introduced that monitors:<br />🧠 The memory address of the EntryPoint<br />🧬 The EntryPoint memory type is changed to PRIVATE<br /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f6d1.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--octagonal_sign" style="height:23px;width:auto;vertical-align:middle" title="🛑" alt="🛑" /> OriginalBase is not valid</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2712.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--black_nib" style="height:23px;width:auto;vertical-align:middle" title="✒" alt="✒" />️  𝐑𝐞𝐚𝐝 𝐭𝐡𝐞 𝐟𝐮𝐥𝐥 𝐚𝐫𝐭𝐢𝐜𝐥𝐞 <a href="https://ipurple.team/2026/05/13/entrypoint-hijacking/" rel="nofollow noopener"><span>https://</span><span>ipurple.team/2026/05/13/entryp</span><span>oint-hijacking/</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/116e60b5-f398-479e-bda6-54d49e046061/entrypoint-hijacking-introduces-a-stealthier-approach-to-code-injection-as-it-doesn-t-use-api-calls-that-create-a-new-thread-within-the-context-of-a-process.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 22:09:40 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/116e60b5-f398-479e-bda6-54d49e046061.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 12:54:52 GMT</pubDate><ttl>60</ttl></channel></rss>