NimPlant icon indicating copy to clipboard operation
NimPlant copied to clipboard

Fix Ekko sleep mask for .dll/.bin payloads

Open chvancooten opened this issue 2 years ago • 1 comments

Currently, the Ekko sleep mask feature only works with the normal executable payloads and not with DLL/shellcode since it targets the parent process' base image for encryption. This is a known issue with Ekko described in this blog.

With some research, the Ekko module could be enhanced to target only the correct section of the present payload for encryption.

chvancooten avatar Feb 13 '23 14:02 chvancooten

hit me up on discord if you need help.

Cracked5pider avatar Feb 17 '23 17:02 Cracked5pider