Nullcon Goa

Phantom Code Evading Windows 11 25H2 Through Posix Based Self Deletion And Stealth Injection

5:35 · 28 Feb 2026 – 01 Mar 2026 · YouTube

About this talk

This talk covers the significant impact of Windows 11 24H2 on malware self-deletion techniques and the challenges it poses for penetration testing. Jakkaraju Varshith and Vivek Joshi from Rashtriya Raksha University explain how the changes to the NTFS driver have made previous self-deletion methods ineffective, leading to recoverable files during forensic analysis. They discuss leveraging the `FILE_DISPOSITION_POSIX_SEMANTICS` flag, originally intended for Windows Subsystem for Linux, to achieve complete and traceless file deletion, as well as the creation of an evasion chain through process injection into explorer.exe to bypass static signature detection.

From event

Nullcon Goa

28 Feb 2026 – 01 Mar 2026

All event videos
Back to Watch