Early Bird Code Injection Technique
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The technique uses legitimate Windows functions such as svhost.exe to inject the code into an application before the actual process starts and the anti-malware product has started to monitor it. Anti-malware products have a process called hooking which is designed to detect this type of technique, however Early Bird loads the malicious code in a very early stage of the start process, this is before many anti-malware’s have placed their hooks so it can go undetected.
Remediation steps
Last edited: 17 February 2020 12:42 pm