<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[From the same author as BlueHammer we now have RedSun.]]></title><description><![CDATA[<p>From the same author as <a href="https://github.com/Nightmare-Eclipse/BlueHammer" rel="nofollow noopener">BlueHammer</a> we now have <a href="https://github.com/Nightmare-Eclipse/RedSun" rel="nofollow noopener">RedSun</a>.</p><p>This works 100% reliably to go from unprivileged user to <code>SYSTEM</code> against Windows 11 and Windows Server with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/412/016/760/812/126/original/af2cf09911b90b83.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/412/016/764/961/933/original/c70c00109489ea5a.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/412/016/775/721/000/original/3fe5485c2580eca2.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/e40e16a1-7954-4794-9b49-e29b9652f8d7/from-the-same-author-as-bluehammer-we-now-have-redsun.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:00:51 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/e40e16a1-7954-4794-9b49-e29b9652f8d7.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 16 Apr 2026 02:27:28 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 16:01:34 GMT]]></title><description><![CDATA[<p>Interestingly, a good chunk of the [(12/73) AV detections on VT](<a href="https://www.virustotal.com/gui/file/d84250e2ad053ab4097d0591933935573e4cab3e975360004a126abc102dc6f6" rel="nofollow noopener"><span>https://www.</span><span>virustotal.com/gui/file/d84250</span><span>e2ad053ab4097d0591933935573e4cab3e975360004a126abc102dc6f6</span></a> for this <code>RedSun.exe</code> exploit are due to the <code>EICAR</code> part being detected, despite the string being reversed in the code. (note: this reversal apparently does nothing to prevent EICAR detection in the AV engines on VT)</p><p>If we make the EICAR string less obvious (encrypted), the <a href="https://www.virustotal.com/gui/file/ba55a1618302dfcf8c09d8eb8346e0a6fb252c2d61d5fa4db8a40cbab475f37e" rel="nofollow noopener">detections drop to 5</a>.</p><p>Defender currently doesn't detect the exploit in either case.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/415/213/239/558/471/original/a69e1517cd06d8cf.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/415/213/817/553/806/original/2b3ad5eb85be4a4e.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116415220573435813</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116415220573435813</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 16:01:34 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 15:49:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f62d.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sob" style="height:23px;width:auto;vertical-align:middle" title="😭" alt="😭" /></p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/qdkp/statuses/116415171470053525</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/qdkp/statuses/116415171470053525</guid><dc:creator><![CDATA[qdkp@cyberplace.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 15:49:05 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 15:47:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/qdkp%40cyberplace.social" rel="nofollow noopener">@<span>qdkp</span></a></span> <br />People don't use OneDrive intentionally, do they?  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f602.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--joy" style="height:23px;width:auto;vertical-align:middle" title="😂" alt="😂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116415164878499235</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116415164878499235</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 15:47:24 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 15:33:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> Thank you. Blocking cldapi.dll using AppLocker works though that will break OneDrive and stuff like that.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/qdkp/statuses/116415111992305979</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/qdkp/statuses/116415111992305979</guid><dc:creator><![CDATA[qdkp@cyberplace.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 15:33:57 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 13:31:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> Yeah, this worked fine. As did the exploit. Thanks for your help! (And for anyone else reading this, the keyboard shortcut to "just compile, don't run" is ctrl-shift-b)</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116414629134895796</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116414629134895796</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 13:31:09 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 12:45:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <br />TBH, for code that doesn't include a <code>.SLN</code> file, I usually have minimal luck compiling it straight-up with <code>cl.exe</code></p><p>In this case, I simply made a new Visual Studio 2022 project for a console app, and then replaced the .CPP file contents with what's in the GitHub repo.  There are a slew of warnings, but it compiles.</p><pre><code>&lt;snip&gt;<br />1&gt;C:\Users\test\source\repos\test\test\test.cpp(431,11): warning C4267: 'initializing': conversion from 'size_t' to 'int', possible loss of data<br />1&gt;C:\Users\test\source\repos\test\test\test.cpp(694,49): warning C4267: '=': conversion from 'size_t' to 'ULONG', possible loss of data<br />1&gt;C:\Users\test\source\repos\test\test\test.cpp(696,92): warning C4267: 'argument': conversion from 'size_t' to 'ULONG', possible loss of data<br />1&gt;C:\Users\test\source\repos\test\test\test.cpp(714,20): warning C4267: 'initializing': conversion from 'size_t' to 'DWORD', possible loss of data<br />1&gt;C:\Users\test\source\repos\test\test\test.cpp(736,57): warning C4838: conversion from 'LONG' to 'DWORD' requires a narrowing conversion<br />1&gt;Generating code<br />1&gt;Previous IPDB not found, fall back to full compilation.<br />1&gt;All 27 functions were compiled because no usable IPDB/IOBJ from previous compilation was found.<br />1&gt;Finished generating code<br />1&gt;test.vcxproj -&gt; C:\Users\test\source\repos\test\x64\Release\test.exe<br />1&gt;Done building project "test.vcxproj".<br />========== Build: 1 succeeded, 0 failed, 0 up-to-date, 0 skipped ==========<br />========== Build completed at 8:43 AM and took 01.818 seconds ==========<br /></code></pre>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116414450404941540</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116414450404941540</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 12:45:42 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 12:23:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> Hey, just so I can learn this: How do I compile RedSun.cpp under Win32 with VS or gcc? I can't seem to include cfapi.h correctly (I have the full win32 sdk under the default location).</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116414363489147094</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116414363489147094</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 12:23:36 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 07:28:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://files.mastodon.social/media_attachments/files/116/413/201/360/162/516/original/748125eba6a12038.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/XC3LL/statuses/116413204443793664</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/XC3LL/statuses/116413204443793664</guid><dc:creator><![CDATA[xc3ll@mastodon.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:28:50 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 04:27:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> Just finished reading through the source, thank you. Much simpler than the first version, and makes the root issue a lot more clear. This is pretty nasty, MS has some serious egg on their faces over this one</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/astraleureka/statuses/116412493150533744</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/astraleureka/statuses/116412493150533744</guid><dc:creator><![CDATA[astraleureka@social.treehouse.systems]]></dc:creator><pubDate>Thu, 16 Apr 2026 04:27:57 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 03:03:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange" rel="nofollow noopener noreferrer">@<span>wdormann</span></a></span> ...or like <a href="https://jorts.horse/tags/PwnPiALOA" rel="tag">#<span>PwnPiALOA</span></a>.<br /><a href="https://www.youtube.com/watch?v=s0K-YIL_G5c" rel="nofollow noopener noreferrer"><span>https://www.</span><span>youtube.com/watch?v=s0K-YIL_G5</span><span>c</span></a></p><p><a href="https://jorts.horse/tags/P4wnP1" rel="tag">#<span>P4wnP1</span></a> <a href="https://jorts.horse/tags/PwnPi" rel="tag">#<span>PwnPi</span></a> <a href="https://jorts.horse/tags/P4wnP1ALOA" rel="tag">#<span>P4wnP1ALOA</span></a> <a href="https://jorts.horse/tags/ALOA" rel="tag">#<span>ALOA</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116412161984193009</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116412161984193009</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Thu, 16 Apr 2026 03:03:44 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 02:58:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange" rel="nofollow noopener noreferrer">@<span>wdormann</span></a></span> I can't wait for this to get <a href="https://jorts.horse/tags/BadUSB" rel="tag">#<span>BadUSB</span></a>'d like <a href="https://jorts.horse/tags/PoisonTap" rel="tag">#<span>PoisonTap</span></a>!</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://www.youtube.com/watch?v=Aatp5gCskvk">
 - YouTube
</a>
</h5>
<p class="card-text line-clamp-3">Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.</p>
</div>
<a href="https://www.youtube.com/watch?v=Aatp5gCskvk" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.youtube.com/s/desktop/d2cf868e/img/favicon_32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />











<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.youtube.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116412140740203336</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116412140740203336</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Thu, 16 Apr 2026 02:58:19 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 02:56:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange" rel="nofollow noopener noreferrer">@<span>wdormann</span></a></span> so basically a <em>"<a href="https://jorts.horse/tags/cloud" rel="tag">#<span>cloud</span></a>-based <a href="https://jorts.horse/tags/utilman" rel="tag">#<span>utilman</span></a>-style "privilegue escalation"</em>?<br /><a href="https://www.youtube.com/watch?v=X_9OuDjl97M" rel="nofollow noopener noreferrer"><span>https://www.</span><span>youtube.com/watch?v=X_9OuDjl97</span><span>M</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116412135458939193</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116412135458939193</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Thu, 16 Apr 2026 02:56:59 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 02:47:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/astraleureka%40social.treehouse.systems" rel="nofollow noopener">@<span>astraleureka</span></a></span> <br />Yes it uses both.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116412096375694323</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116412096375694323</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 02:47:02 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 02:46:46 GMT]]></title><description><![CDATA[<p>From the GitHub repo:</p><blockquote><p>When Windows Defender realizes that a malicious file has a cloud tag, for whatever stupid and hilarious reason, the antivirus that's supposed to protect decides that it is a good idea to just rewrite the file it found again to it's original location.</p></blockquote><p>This Exploit uses the "Cloud Files API", writes EICAR to a file using it, uses an oplock to win a volume shadow copy race, and uses a directory junction/reparse point to redirect the file rewrite (with new contents) to <code>C:\Windows\system32\TieringEngineService.exe</code>.  At this point, the Cloud Files Infrastructure runs <code>TieringEngineService.exe</code> as <code>SYSTEM</code>.  Game over.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116412095326913592</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116412095326913592</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 02:46:46 GMT</pubDate></item><item><title><![CDATA[Reply to From the same author as BlueHammer we now have RedSun. on Thu, 16 Apr 2026 02:38:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> Does it still depend on VSS and the cloud storage filter subsystem?</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/astraleureka/statuses/116412062907410124</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/astraleureka/statuses/116412062907410124</guid><dc:creator><![CDATA[astraleureka@social.treehouse.systems]]></dc:creator><pubDate>Thu, 16 Apr 2026 02:38:32 GMT</pubDate></item></channel></rss>