Nullcon Goa 2025: The Hidden ART Of Rolling Shellcode Decryption - Tijme Gommers
About this talk
This talk introduces Kong Loader, an innovative approach to loading shellcode that ensures malware remains completely hidden in memory during execution. The speaker explains how Kong Loader decrypts each assembly instruction on-the-fly, executes it, and then re-encrypts it, making only the currently executing instruction visible in memory. This method significantly enhances protection against detection by endpoint detection and response (EDR) systems and other security measures.
More from this event
See all 30 talks →
Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains
38:14
Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin
26:30
Nullcon Goa 2025 | Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
44:47
Nullcon Goa 2025: Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
42:01