Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. May 11, 2026: The Red Sun still prevails.

May 11, 2026: The Red Sun still prevails.

Scheduled Pinned Locked Moved Uncategorized
43 Posts 5 Posters 226 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jhr77@mastodon.socialJ jhr77@mastodon.social

    @christopherkunz Possibly the defender then has reached his working temperature...

    christopherkunz@chaos.socialC This user is from outside of this forum
    christopherkunz@chaos.socialC This user is from outside of this forum
    christopherkunz@chaos.social
    wrote last edited by
    #3

    @jhr77 I retried later during the day yesterday and it seems that the exploit sometimes gets stuck trying to win the race condition, but generally still works even on a "warm" computer.

    1 Reply Last reply
    0
    • christopherkunz@chaos.socialC christopherkunz@chaos.social

      May 11, 2026: The Red Sun still prevails.

      However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

      jhr77@mastodon.socialJ This user is from outside of this forum
      jhr77@mastodon.socialJ This user is from outside of this forum
      jhr77@mastodon.social
      wrote last edited by
      #4

      @christopherkunz maybe it's linked to system load or a half-working patch from MS...
      It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
      br

      christopherkunz@chaos.socialC wdormann@infosec.exchangeW 2 Replies Last reply
      0
      • jhr77@mastodon.socialJ jhr77@mastodon.social

        @christopherkunz maybe it's linked to system load or a half-working patch from MS...
        It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
        br

        christopherkunz@chaos.socialC This user is from outside of this forum
        christopherkunz@chaos.socialC This user is from outside of this forum
        christopherkunz@chaos.social
        wrote last edited by
        #5

        @jhr77 It works on both, because it's only dependent on Defender and NTFS being available, no physical/hardware constraints as far as I can tell. I suspect it's going away tomorrow, so
        a) try it out today, and
        b) watch the author's Github tomorrow.

        jhr77@mastodon.socialJ 1 Reply Last reply
        0
        • christopherkunz@chaos.socialC christopherkunz@chaos.social

          @jhr77 It works on both, because it's only dependent on Defender and NTFS being available, no physical/hardware constraints as far as I can tell. I suspect it's going away tomorrow, so
          a) try it out today, and
          b) watch the author's Github tomorrow.

          jhr77@mastodon.socialJ This user is from outside of this forum
          jhr77@mastodon.socialJ This user is from outside of this forum
          jhr77@mastodon.social
          wrote last edited by
          #6

          @christopherkunz just installing visual studio....

          christopherkunz@chaos.socialC 1 Reply Last reply
          0
          • jhr77@mastodon.socialJ jhr77@mastodon.social

            @christopherkunz just installing visual studio....

            christopherkunz@chaos.socialC This user is from outside of this forum
            christopherkunz@chaos.socialC This user is from outside of this forum
            christopherkunz@chaos.social
            wrote last edited by
            #7

            @jhr77 I got a great advice from @wdormann - create an example project, delete the main.cpp and paste RedSun stuff. That way, dependencies are already set and you'll have an easier time compiling.

            jhr77@mastodon.socialJ 1 Reply Last reply
            0
            • christopherkunz@chaos.socialC christopherkunz@chaos.social

              May 11, 2026: The Red Sun still prevails.

              However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

              jhr77@mastodon.socialJ This user is from outside of this forum
              jhr77@mastodon.socialJ This user is from outside of this forum
              jhr77@mastodon.social
              wrote last edited by
              #8

              @christopherkunz This is all too simple. Copy.Fail:just execute a python script. RedSun - just compile and run...

              1 Reply Last reply
              0
              • christopherkunz@chaos.socialC christopherkunz@chaos.social

                @jhr77 I got a great advice from @wdormann - create an example project, delete the main.cpp and paste RedSun stuff. That way, dependencies are already set and you'll have an easier time compiling.

                jhr77@mastodon.socialJ This user is from outside of this forum
                jhr77@mastodon.socialJ This user is from outside of this forum
                jhr77@mastodon.social
                wrote last edited by
                #9

                @christopherkunz @wdormann it worked from the scratch. Just a new project and the cpp file as source. Compile and run...

                1 Reply Last reply
                0
                • jhr77@mastodon.socialJ jhr77@mastodon.social

                  @christopherkunz maybe it's linked to system load or a half-working patch from MS...
                  It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
                  br

                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchange
                  wrote last edited by
                  #10

                  @jhr77 @christopherkunz
                  I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

                  With current definitions, I've not seen RedSun succeed. No matter how long I wait.

                  With old definitions, success is pretty quick.

                  christopherkunz@chaos.socialC buherator@infosec.placeB 2 Replies Last reply
                  0
                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                    @jhr77 @christopherkunz
                    I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

                    With current definitions, I've not seen RedSun succeed. No matter how long I wait.

                    With old definitions, success is pretty quick.

                    christopherkunz@chaos.socialC This user is from outside of this forum
                    christopherkunz@chaos.socialC This user is from outside of this forum
                    christopherkunz@chaos.social
                    wrote last edited by
                    #11

                    @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

                    Link Preview Image
                    gossithedog@cyberplace.socialG 1 Reply Last reply
                    0
                    • christopherkunz@chaos.socialC christopherkunz@chaos.social

                      @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

                      Link Preview Image
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      wrote last edited by
                      #12

                      @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                      wdormann@infosec.exchangeW christopherkunz@chaos.socialC 2 Replies Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchange
                        wrote last edited by
                        #13

                        @GossiTheDog @christopherkunz @jhr77
                        Cloud-delivered protection ?
                        If so, then yeah, it's on.
                        It's the same stock Win11 VM that worked in April. Just with Defender updates installed.

                        Link Preview Image
                        christopherkunz@chaos.socialC 1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                          christopherkunz@chaos.socialC This user is from outside of this forum
                          christopherkunz@chaos.socialC This user is from outside of this forum
                          christopherkunz@chaos.social
                          wrote last edited by
                          #14

                          @GossiTheDog @wdormann @jhr77 Yes, cloud protection is on. This is a German Win11 Home, I think. After updating to today's definitions and a reboot, RedSun.exe doesn't seem to win the RC anymore, so the reboot was likely necessary to apply the Defender mitigation.
                          I don't think this is merely a signature update, from what I understood the mitigation requires a core update to Defender.

                          wdormann@infosec.exchangeW 1 Reply Last reply
                          0
                          • christopherkunz@chaos.socialC christopherkunz@chaos.social

                            @GossiTheDog @wdormann @jhr77 Yes, cloud protection is on. This is a German Win11 Home, I think. After updating to today's definitions and a reboot, RedSun.exe doesn't seem to win the RC anymore, so the reboot was likely necessary to apply the Defender mitigation.
                            I don't think this is merely a signature update, from what I understood the mitigation requires a core update to Defender.

                            wdormann@infosec.exchangeW This user is from outside of this forum
                            wdormann@infosec.exchangeW This user is from outside of this forum
                            wdormann@infosec.exchange
                            wrote last edited by
                            #15

                            @christopherkunz @GossiTheDog @jhr77
                            The executable bits for Defender are updated along with sigs.

                            christopherkunz@chaos.socialC 1 Reply Last reply
                            0
                            • wdormann@infosec.exchangeW wdormann@infosec.exchange

                              @christopherkunz @GossiTheDog @jhr77
                              The executable bits for Defender are updated along with sigs.

                              christopherkunz@chaos.socialC This user is from outside of this forum
                              christopherkunz@chaos.socialC This user is from outside of this forum
                              christopherkunz@chaos.social
                              wrote last edited by
                              #16

                              @wdormann @GossiTheDog @jhr77 On second attempt, the exploit worked. So whatever MS did, is still not a 100% mitigation. I''ll try again to reproduce what happened.

                              wdormann@infosec.exchangeW 1 Reply Last reply
                              0
                              • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                @wdormann @GossiTheDog @jhr77 On second attempt, the exploit worked. So whatever MS did, is still not a 100% mitigation. I''ll try again to reproduce what happened.

                                wdormann@infosec.exchangeW This user is from outside of this forum
                                wdormann@infosec.exchangeW This user is from outside of this forum
                                wdormann@infosec.exchange
                                wrote last edited by
                                #17

                                @christopherkunz @GossiTheDog @jhr77
                                When it succeeds, does it happen relatively quickly?

                                I've tried both waiting 10 minutes and have also tried 10 times in a row, and neither strategy is successful on my Win11 VM.

                                1 Reply Last reply
                                0
                                • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                  @GossiTheDog @christopherkunz @jhr77
                                  Cloud-delivered protection ?
                                  If so, then yeah, it's on.
                                  It's the same stock Win11 VM that worked in April. Just with Defender updates installed.

                                  Link Preview Image
                                  christopherkunz@chaos.socialC This user is from outside of this forum
                                  christopherkunz@chaos.socialC This user is from outside of this forum
                                  christopherkunz@chaos.social
                                  wrote last edited by
                                  #18

                                  @wdormann @GossiTheDog @jhr77 Reboot, log in, win-r, cmd, cd \temp, RedSun.exe, worked on first attempt.
                                  In my last attempt, I had opened the Defender warning popup "defender has found a threat" and I thought I'd triggered some condition for the exploit to work. Seems not, I can still run it.
                                  It succeeds after about 10 seconds.

                                  wdormann@infosec.exchangeW 1 Reply Last reply
                                  0
                                  • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                    @wdormann @GossiTheDog @jhr77 Reboot, log in, win-r, cmd, cd \temp, RedSun.exe, worked on first attempt.
                                    In my last attempt, I had opened the Defender warning popup "defender has found a threat" and I thought I'd triggered some condition for the exploit to work. Seems not, I can still run it.
                                    It succeeds after about 10 seconds.

                                    wdormann@infosec.exchangeW This user is from outside of this forum
                                    wdormann@infosec.exchangeW This user is from outside of this forum
                                    wdormann@infosec.exchange
                                    wrote last edited by
                                    #19

                                    @christopherkunz @GossiTheDog @jhr77
                                    The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                                    It's just that at least for me, it never succeeds with updated defs. 🤷‍♂️

                                    Link Preview Image
                                    christopherkunz@chaos.socialC 2 Replies Last reply
                                    0
                                    • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                      @christopherkunz @GossiTheDog @jhr77
                                      The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                                      It's just that at least for me, it never succeeds with updated defs. 🤷‍♂️

                                      Link Preview Image
                                      christopherkunz@chaos.socialC This user is from outside of this forum
                                      christopherkunz@chaos.socialC This user is from outside of this forum
                                      christopherkunz@chaos.social
                                      wrote last edited by
                                      #20

                                      @wdormann @GossiTheDog @jhr77 Yeah, the first dialog is the detection of EICAR, the second one is the admission of defeat. I get both, and a NT_AUTHORITY shell, on running RedSun.exe.
                                      This is weird, but I suspect we're basically arguing against a ticking clock here. Patch day will land soon and with it, undoubtedly a RedSun mitigation. Actually, let me milk this opportunity for a meme.

                                      Link Preview Image
                                      1 Reply Last reply
                                      0
                                      • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                        @christopherkunz @GossiTheDog @jhr77
                                        The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                                        It's just that at least for me, it never succeeds with updated defs. 🤷‍♂️

                                        Link Preview Image
                                        christopherkunz@chaos.socialC This user is from outside of this forum
                                        christopherkunz@chaos.socialC This user is from outside of this forum
                                        christopherkunz@chaos.social
                                        wrote last edited by
                                        #21

                                        @wdormann @GossiTheDog @jhr77 I think my TieringEngineService.exe might be permanently patched/replaced with the RedSun copy and none of the definitions updates have cleaned it up.

                                        wdormann@infosec.exchangeW 1 Reply Last reply
                                        0
                                        • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                          @wdormann @GossiTheDog @jhr77 I think my TieringEngineService.exe might be permanently patched/replaced with the RedSun copy and none of the definitions updates have cleaned it up.

                                          wdormann@infosec.exchangeW This user is from outside of this forum
                                          wdormann@infosec.exchangeW This user is from outside of this forum
                                          wdormann@infosec.exchange
                                          wrote last edited by
                                          #22

                                          @christopherkunz @GossiTheDog @jhr77
                                          Well yep, if you're testing on an already-popped machine, that's an invalid test.

                                          That is, if C:\Windows\system32\TieringEngineService.exe has already been replaced, then the exploit might appear to "work" even when it doesn't.

                                          TieringEngineService.exe is a Windows component. It has nothing to do with Defender, and no Defender update will restore it to its pristine state.

                                          wdormann@infosec.exchangeW 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups