Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. May 11, 2026: The Red Sun still prevails.

May 11, 2026: The Red Sun still prevails.

Scheduled Pinned Locked Moved Uncategorized
43 Posts 5 Posters 226 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • christopherkunz@chaos.socialC christopherkunz@chaos.social

    May 11, 2026: The Red Sun still prevails.

    However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

    jhr77@mastodon.socialJ This user is from outside of this forum
    jhr77@mastodon.socialJ This user is from outside of this forum
    jhr77@mastodon.social
    wrote last edited by
    #8

    @christopherkunz This is all too simple. Copy.Fail:just execute a python script. RedSun - just compile and run...

    1 Reply Last reply
    0
    • christopherkunz@chaos.socialC christopherkunz@chaos.social

      @jhr77 I got a great advice from @wdormann - create an example project, delete the main.cpp and paste RedSun stuff. That way, dependencies are already set and you'll have an easier time compiling.

      jhr77@mastodon.socialJ This user is from outside of this forum
      jhr77@mastodon.socialJ This user is from outside of this forum
      jhr77@mastodon.social
      wrote last edited by
      #9

      @christopherkunz @wdormann it worked from the scratch. Just a new project and the cpp file as source. Compile and run...

      1 Reply Last reply
      0
      • jhr77@mastodon.socialJ jhr77@mastodon.social

        @christopherkunz maybe it's linked to system load or a half-working patch from MS...
        It will be interesting to try out. If I find the time to set-up a VM or are you trying on a physical computer?
        br

        wdormann@infosec.exchangeW This user is from outside of this forum
        wdormann@infosec.exchangeW This user is from outside of this forum
        wdormann@infosec.exchange
        wrote last edited by
        #10

        @jhr77 @christopherkunz
        I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

        With current definitions, I've not seen RedSun succeed. No matter how long I wait.

        With old definitions, success is pretty quick.

        christopherkunz@chaos.socialC buherator@infosec.placeB 2 Replies Last reply
        0
        • wdormann@infosec.exchangeW wdormann@infosec.exchange

          @jhr77 @christopherkunz
          I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

          With current definitions, I've not seen RedSun succeed. No matter how long I wait.

          With old definitions, success is pretty quick.

          christopherkunz@chaos.socialC This user is from outside of this forum
          christopherkunz@chaos.socialC This user is from outside of this forum
          christopherkunz@chaos.social
          wrote last edited by
          #11

          @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

          Link Preview Image
          gossithedog@cyberplace.socialG 1 Reply Last reply
          0
          • christopherkunz@chaos.socialC christopherkunz@chaos.social

            @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

            Link Preview Image
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            wrote last edited by
            #12

            @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

            wdormann@infosec.exchangeW christopherkunz@chaos.socialC 2 Replies Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchange
              wrote last edited by
              #13

              @GossiTheDog @christopherkunz @jhr77
              Cloud-delivered protection ?
              If so, then yeah, it's on.
              It's the same stock Win11 VM that worked in April. Just with Defender updates installed.

              Link Preview Image
              christopherkunz@chaos.socialC 1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                @christopherkunz @wdormann @jhr77 do you have cloud protection turned on?

                christopherkunz@chaos.socialC This user is from outside of this forum
                christopherkunz@chaos.socialC This user is from outside of this forum
                christopherkunz@chaos.social
                wrote last edited by
                #14

                @GossiTheDog @wdormann @jhr77 Yes, cloud protection is on. This is a German Win11 Home, I think. After updating to today's definitions and a reboot, RedSun.exe doesn't seem to win the RC anymore, so the reboot was likely necessary to apply the Defender mitigation.
                I don't think this is merely a signature update, from what I understood the mitigation requires a core update to Defender.

                wdormann@infosec.exchangeW 1 Reply Last reply
                0
                • christopherkunz@chaos.socialC christopherkunz@chaos.social

                  @GossiTheDog @wdormann @jhr77 Yes, cloud protection is on. This is a German Win11 Home, I think. After updating to today's definitions and a reboot, RedSun.exe doesn't seem to win the RC anymore, so the reboot was likely necessary to apply the Defender mitigation.
                  I don't think this is merely a signature update, from what I understood the mitigation requires a core update to Defender.

                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchange
                  wrote last edited by
                  #15

                  @christopherkunz @GossiTheDog @jhr77
                  The executable bits for Defender are updated along with sigs.

                  christopherkunz@chaos.socialC 1 Reply Last reply
                  0
                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                    @christopherkunz @GossiTheDog @jhr77
                    The executable bits for Defender are updated along with sigs.

                    christopherkunz@chaos.socialC This user is from outside of this forum
                    christopherkunz@chaos.socialC This user is from outside of this forum
                    christopherkunz@chaos.social
                    wrote last edited by
                    #16

                    @wdormann @GossiTheDog @jhr77 On second attempt, the exploit worked. So whatever MS did, is still not a 100% mitigation. I''ll try again to reproduce what happened.

                    wdormann@infosec.exchangeW 1 Reply Last reply
                    0
                    • christopherkunz@chaos.socialC christopherkunz@chaos.social

                      @wdormann @GossiTheDog @jhr77 On second attempt, the exploit worked. So whatever MS did, is still not a 100% mitigation. I''ll try again to reproduce what happened.

                      wdormann@infosec.exchangeW This user is from outside of this forum
                      wdormann@infosec.exchangeW This user is from outside of this forum
                      wdormann@infosec.exchange
                      wrote last edited by
                      #17

                      @christopherkunz @GossiTheDog @jhr77
                      When it succeeds, does it happen relatively quickly?

                      I've tried both waiting 10 minutes and have also tried 10 times in a row, and neither strategy is successful on my Win11 VM.

                      1 Reply Last reply
                      0
                      • wdormann@infosec.exchangeW wdormann@infosec.exchange

                        @GossiTheDog @christopherkunz @jhr77
                        Cloud-delivered protection ?
                        If so, then yeah, it's on.
                        It's the same stock Win11 VM that worked in April. Just with Defender updates installed.

                        Link Preview Image
                        christopherkunz@chaos.socialC This user is from outside of this forum
                        christopherkunz@chaos.socialC This user is from outside of this forum
                        christopherkunz@chaos.social
                        wrote last edited by
                        #18

                        @wdormann @GossiTheDog @jhr77 Reboot, log in, win-r, cmd, cd \temp, RedSun.exe, worked on first attempt.
                        In my last attempt, I had opened the Defender warning popup "defender has found a threat" and I thought I'd triggered some condition for the exploit to work. Seems not, I can still run it.
                        It succeeds after about 10 seconds.

                        wdormann@infosec.exchangeW 1 Reply Last reply
                        0
                        • christopherkunz@chaos.socialC christopherkunz@chaos.social

                          @wdormann @GossiTheDog @jhr77 Reboot, log in, win-r, cmd, cd \temp, RedSun.exe, worked on first attempt.
                          In my last attempt, I had opened the Defender warning popup "defender has found a threat" and I thought I'd triggered some condition for the exploit to work. Seems not, I can still run it.
                          It succeeds after about 10 seconds.

                          wdormann@infosec.exchangeW This user is from outside of this forum
                          wdormann@infosec.exchangeW This user is from outside of this forum
                          wdormann@infosec.exchange
                          wrote last edited by
                          #19

                          @christopherkunz @GossiTheDog @jhr77
                          The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                          It's just that at least for me, it never succeeds with updated defs. πŸ€·β€β™‚οΈ

                          Link Preview Image
                          christopherkunz@chaos.socialC 2 Replies Last reply
                          0
                          • wdormann@infosec.exchangeW wdormann@infosec.exchange

                            @christopherkunz @GossiTheDog @jhr77
                            The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                            It's just that at least for me, it never succeeds with updated defs. πŸ€·β€β™‚οΈ

                            Link Preview Image
                            christopherkunz@chaos.socialC This user is from outside of this forum
                            christopherkunz@chaos.socialC This user is from outside of this forum
                            christopherkunz@chaos.social
                            wrote last edited by
                            #20

                            @wdormann @GossiTheDog @jhr77 Yeah, the first dialog is the detection of EICAR, the second one is the admission of defeat. I get both, and a NT_AUTHORITY shell, on running RedSun.exe.
                            This is weird, but I suspect we're basically arguing against a ticking clock here. Patch day will land soon and with it, undoubtedly a RedSun mitigation. Actually, let me milk this opportunity for a meme.

                            Link Preview Image
                            1 Reply Last reply
                            0
                            • wdormann@infosec.exchangeW wdormann@infosec.exchange

                              @christopherkunz @GossiTheDog @jhr77
                              The dialog is the detection of the EICAR TieringEngineService.exe and is definitely a part of the successful exploit flow.

                              It's just that at least for me, it never succeeds with updated defs. πŸ€·β€β™‚οΈ

                              Link Preview Image
                              christopherkunz@chaos.socialC This user is from outside of this forum
                              christopherkunz@chaos.socialC This user is from outside of this forum
                              christopherkunz@chaos.social
                              wrote last edited by
                              #21

                              @wdormann @GossiTheDog @jhr77 I think my TieringEngineService.exe might be permanently patched/replaced with the RedSun copy and none of the definitions updates have cleaned it up.

                              wdormann@infosec.exchangeW 1 Reply Last reply
                              0
                              • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                @wdormann @GossiTheDog @jhr77 I think my TieringEngineService.exe might be permanently patched/replaced with the RedSun copy and none of the definitions updates have cleaned it up.

                                wdormann@infosec.exchangeW This user is from outside of this forum
                                wdormann@infosec.exchangeW This user is from outside of this forum
                                wdormann@infosec.exchange
                                wrote last edited by
                                #22

                                @christopherkunz @GossiTheDog @jhr77
                                Well yep, if you're testing on an already-popped machine, that's an invalid test.

                                That is, if C:\Windows\system32\TieringEngineService.exe has already been replaced, then the exploit might appear to "work" even when it doesn't.

                                TieringEngineService.exe is a Windows component. It has nothing to do with Defender, and no Defender update will restore it to its pristine state.

                                wdormann@infosec.exchangeW 1 Reply Last reply
                                0
                                • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                  @christopherkunz @GossiTheDog @jhr77
                                  Well yep, if you're testing on an already-popped machine, that's an invalid test.

                                  That is, if C:\Windows\system32\TieringEngineService.exe has already been replaced, then the exploit might appear to "work" even when it doesn't.

                                  TieringEngineService.exe is a Windows component. It has nothing to do with Defender, and no Defender update will restore it to its pristine state.

                                  wdormann@infosec.exchangeW This user is from outside of this forum
                                  wdormann@infosec.exchangeW This user is from outside of this forum
                                  wdormann@infosec.exchange
                                  wrote last edited by
                                  #23

                                  @christopherkunz @GossiTheDog @jhr77

                                  Though I'll also admit that having Windows Security open seems to indicate that Windows Defender stops when RedSun is attempted.

                                  From the GUI it's merely Threat service has stopped, but in Event viewer we can get more info in that it's Microsoft Defender Antivirus has encountered a critical error when taking action on malware or other potentially unwanted software.

                                  It restarts automatically.

                                  If this is an intentional RedSun fix, I'll say that it's less than ideal. πŸ˜‚

                                  Link Preview ImageLink Preview Image
                                  jhr77@mastodon.socialJ 1 Reply Last reply
                                  0
                                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                    @christopherkunz @GossiTheDog @jhr77

                                    Though I'll also admit that having Windows Security open seems to indicate that Windows Defender stops when RedSun is attempted.

                                    From the GUI it's merely Threat service has stopped, but in Event viewer we can get more info in that it's Microsoft Defender Antivirus has encountered a critical error when taking action on malware or other potentially unwanted software.

                                    It restarts automatically.

                                    If this is an intentional RedSun fix, I'll say that it's less than ideal. πŸ˜‚

                                    Link Preview ImageLink Preview Image
                                    jhr77@mastodon.socialJ This user is from outside of this forum
                                    jhr77@mastodon.socialJ This user is from outside of this forum
                                    jhr77@mastodon.social
                                    wrote last edited by
                                    #24

                                    @wdormann @christopherkunz @GossiTheDog Hi, today at the first try I had a shell with system rights. So i assume that it worked successfully.

                                    wdormann@infosec.exchangeW 1 Reply Last reply
                                    0
                                    • jhr77@mastodon.socialJ jhr77@mastodon.social

                                      @wdormann @christopherkunz @GossiTheDog Hi, today at the first try I had a shell with system rights. So i assume that it worked successfully.

                                      wdormann@infosec.exchangeW This user is from outside of this forum
                                      wdormann@infosec.exchangeW This user is from outside of this forum
                                      wdormann@infosec.exchange
                                      wrote last edited by
                                      #25

                                      @jhr77 @christopherkunz @GossiTheDog

                                      Just to be clear, before you attempted the exploit, your C:\Windows\system32\TieringEngineService.exe file had a valid signature?

                                      Link Preview ImageLink Preview Image
                                      jhr77@mastodon.socialJ christopherkunz@chaos.socialC 2 Replies Last reply
                                      0
                                      • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                        @jhr77 @christopherkunz @GossiTheDog

                                        Just to be clear, before you attempted the exploit, your C:\Windows\system32\TieringEngineService.exe file had a valid signature?

                                        Link Preview ImageLink Preview Image
                                        jhr77@mastodon.socialJ This user is from outside of this forum
                                        jhr77@mastodon.socialJ This user is from outside of this forum
                                        jhr77@mastodon.social
                                        wrote last edited by
                                        #26

                                        @wdormann @christopherkunz @GossiTheDog So this is even worse as this is persistent

                                        wdormann@infosec.exchangeW 1 Reply Last reply
                                        0
                                        • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                          @jhr77 @christopherkunz @GossiTheDog

                                          Just to be clear, before you attempted the exploit, your C:\Windows\system32\TieringEngineService.exe file had a valid signature?

                                          Link Preview ImageLink Preview Image
                                          christopherkunz@chaos.socialC This user is from outside of this forum
                                          christopherkunz@chaos.socialC This user is from outside of this forum
                                          christopherkunz@chaos.social
                                          wrote last edited by
                                          #27

                                          @wdormann @jhr77 @GossiTheDog Yeah, mine is unsigned, so I'm doing the whole dism & sfc routine now to presumably fix it.
                                          I'm a little surprised though: Is this normal behavior that unsigned corrupted executables remain indefinitely in \system32 and aren't detected or removed? Is this something I would have to trigger manually, like an offline scan of sorts?

                                          jhr77@mastodon.socialJ wdormann@infosec.exchangeW 2 Replies Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups