Nullcon Goa 2025: The Hidden ART Of Rolling Shellcode Decryption - Tijme Gommers

30:02 · 01 Mar 2025 – 02 Mar 2025 · YouTube

About this talk

This talk introduces Kong Loader, an innovative approach to loading shellcode that ensures malware remains completely hidden in memory during execution. The speaker explains how Kong Loader decrypts each assembly instruction on-the-fly, executes it, and then re-encrypts it, making only the currently executing instruction visible in memory. This method significantly enhances protection against detection by endpoint detection and response (EDR) systems and other security measures.

From event

Nullcon Goa 2025

01 Mar 2025 – 02 Mar 2025

All event videos
Back to Watch