StackMoonwalk: A novel approach to stack spoofing on Windows x64
Stackmoonwalk
A novel approach to stack spoofing on
Windows x64
Alessandro Magnosi 13/08/2023
Arash Parsa
Athanasios Tserpelis
1
DEF CON 31: STAC KMOONWALK
WHo WE Are
Alessandro Athanasios
Magnosi Tserpelis
Arash Parsa
2
DEF CON 31: STAC KMOONWALK
WHo WE Are
Alessandro
Magnosi
3
DEF CON 31: STAC KMOONWALK
WHo WE Are
Alessandro Athanasios
Magnosi Tserpelis
Arash Parsa
4
DEF CON 31: STAC KMOONWALK
WHo WE Are
Alessandro Athanasios
Magnosi Tserpelis
Arash Parsa
5
DEF CON 31: STAC KMOONWALK
Who We ARE
Alessandro Athanasios
Magnosi Tserpelis
Arash Parsa
6
DEF CON 31: STAC KMOONWALK
TIMELINE
Q3 2022 Q4 2022 Q1 2023 Q2 2023
NAMAZSO POC
WINDOWS STACK R&D
DEVELOPING BASE FOR FRAME SELECTION
DEVELOP FULL MOON
ADDITIONAL RESEARCH AVENUES
7
StackMoonwalk: A novel approach to stack spoofing on Windows x64
BACKGROUND &
PREVIOUS WORK
8
DEF CON 31: STAC KMOONWALK
Define STACK SPOOFING
9
DEF CON 31: STAC KMOONWALK
THread Call Stack
10
DEF CON 31: STAC KMOONWALK
Unwinding
11
DEF CON 31: STAC KMOONWALK
Unwinding
12
DEF CON 31: STAC KMOONWALK
Unwinding
13
DEF CON 31: STAC KMOONWALK
WINDOWS CALLING CONVENTION
Mexico
[Link] 14
DEF CON 31: STAC KMOONWALK
Call-Stack Analysis
In-Memory Execution In-Direct System Calls
When a particular API or system call is executed, Although rarely used for this reason, analyzing
Call Stack analysis can be utilised to trace back the call stack can be used to identify situation
the caller frame and verify if it can be resolved whereby a system call has been invoked directly
to a module on disk. via an Nt function or by using an indirect jump.
15
DEF CON 31: STAC KMOONWALK
In-memory Execution
Normal Call Stack In-Memory Code Call Stack
16
DEF CON 31: STAC KMOONWALK
in-memory ExEcution - STOMPING
17
DEF CON 31: STAC KMOONWALK
InDirect Syscall Execution
High Level API Call Stack Indirect Syscall Call Stack
18
DEF CON 31: STAC KMOONWALK
When to detect
Conditional
Periodic Hooking
Every A security tool might scan Every
period of T seconds all time a specific API or
all threads in a WAIT state
threads can be scanned System Call gets called, the
and their call stack analysed to check for sleeping call stack can be analysed
implants
19
DEF CON 31: STAC KMOONWALK
Previous RESEARCH
1 2 3 4
Stack Truncation Stack Crafting Stack Cloning Stack Hiding
This is an extension of return Craft the thread call stack Uses an external mechanism Uses Fibers to hide the
address spoofing, which artificially, to mimic other (timers, APC queues) to hide thread stack of the in-
ensure to zero out the return legitimate threads when the thread stack of the in- memory injected code
address of the caller frame invoking a specific API memory injected code by
cloning a legitimate thread
stack
20
DEF CON 31: STAC KMOONWALK
STACK TRUNCATION
21
DEF CON 31: STAC KMOONWALK
STACK TRUNCATION
22
DEF CON 31: STAC KMOONWALK
STACK TRUNCATION
23
DEF CON 31: STAC KMOONWALK
STACK CRAFTING
24
DEF CON 31: STAC KMOONWALK
STACK CRAFTING
25
DEF CON 31: STAC KMOONWALK
STACK CLONING
26
DEF CON 31: STAC KMOONWALK
STACK CLONING
27
DEF CON 31: STAC KMOONWALK
STACK HIDING
28
DEF CON 31: STAC KMOONWALK
STACK HIDING
29
DEF CON 31: STAC KMOONWALK
STACK HIDING
30
StackMoonwalk: A novel approach to stack spoofing on Windows x64
Our CONTRIBUTION
31
DEF CON 31: STAC KMOONWALK
STACK MOONWWALKING
Hide Caller Obfuscate Stack Auto Restore
1 This technique was initially
developed to conceal the main
caller module from the call
stack, preseriving its
unwindability when executing
2 Stack Moonwalk obfuscates
the stack, making it difficult to
understand how a specific
API/System Call was invoked
3 The technique does not use
any external mechanism to
restore the stack on return, it
does use a ROP paradigm
instead
in-memory code
32
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
33
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
34
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
35
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
36
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
37
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
38
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK)
39
DEF CON 31: STAC KMOONWALK
FULL MOON (WALK) - FRAMES
40
DEF CON 31: STAC KMOONWALK
Eclipse
41
DEF CON 31: STAC KMOONWALK
Eclipse
42
DEF CON 31: STAC KMOONWALK
ECLipse - Algorithm
43
DEF CON 31: STAC KMOONWALK
Eclipse - IN ACTION
44
DEF CON 31: STAC KMOONWALK
Eclipse - IN ACTION
45
DEF CON 31: STAC KMOONWALK
Eclipse - IN ACTION
46
DEF CON 31: STAC KMOONWALK
ECLipse - False Positives
47
DEF CON 31: STAC KMOONWALK
ECLipse - ACCURACY and JIT
Number of Processes
Number of processes with anomalies
False Positives
48
DEF CON 31: STAC KMOONWALK
HALF Moon (WALK)
49
DEF CON 31: STAC KMOONWALK
HALF Moon (WALK)
50
DEF CON 31: STAC KMOONWALK
HALF Moon (WALK) - RETURN FLOW
Place Return Targeted Sliding HW
1 2 3
on Unwinding Setup breakpoints
It is possible to set the return It is also possible to analyze It is possible to use a "sliding
address at the start of the and tamper the post-return breakpoint" strategy to force
epilogue, which can be calculated checks to ensure the program the return flow in a suitable
using the RUNTIME_FUNCTION returns without errors. way.
information.
51
DEF CON 31: STAC KMOONWALK
HALF Moon (WALK) - RETURN ON EPILOG
52
DEF CON 31: STAC KMOONWALK
HALF Moon (WALK) - TargetED SETUP
53
DEF CON 31: STAC KMOONWALK
HALF Moon (WALK) - SLIDING HWBP
54
DEF CON 31: STAC KMOONWALK
OPAQUE ARCHITECTURE
55
DEF CON 31: STAC KMOONWALK
OPAQUE ARCHITECTURE - RPC
56
DEF CON 31: STAC KMOONWALK
OPAQUE ARCHITECTURE - RPC
TARGET FUNCTION
High Level API N
... HalfMoon
rtprt4!Invoke+0x?
Shellcode Frame N
....
Text Size: 0x5B0 + x NdrStubCall2Stack
Shellcode Frame 1 Frame
rtprt4!NdrStubCall2+0x?
Set Thread Context
rtprt4!NdrServerCall2+0x?
BaseThreadInitThunk+0x?
Start Thread
RtlUserThreadStart+0x?
(Suspended)
57
DEF CON 31: STAC KMOONWALK
OPAQUE ARCHITECTURE - RPC
TARGET FUNCTION
High Level API N
... HalfMoon
rtprt4!Invoke+0x?
Shellcode Frame N
Text
.... NdrStubCall2Stack
Size
Shellcode Frame 1 Frame
0x5B0 + 0x38
rtprt4!NdrStubCall2+0x?
Set Thread Context
rtprt4!NdrServerCall2+0x?
BaseThreadInitThunk+0x?
Start Thread
RtlUserThreadStart+0x?
(Suspended)
58
DEF CON 31: STAC KMOONWALK
ABOUT INTEL CET
59
DEF CON 31: STAC KMOONWALK
Key Takeaways Public POC Available
[Link]
It adds a layer of complexity which is not It is possible to create chains of different
always easy to manage length by inserting stack pivot frames
Full Moon obfuscate the caller frames but
This POC is designed to obfuscate the stack at
creates inconsistences across frames. Half
runtime, and can be used wherever return Moon and its variations, instead, require
address spoofing is used executable memory (Exception Handlers) to
restore the stack on return
For sleep obfuscation an approach like Stack It is possible to integrate full encryption of the
code at runtime (i.e. sleep encryption)
Hiding or Stack Cloning is preferred whenever an API is invoked
60
DEF CON 31: STAC KMOONWALK
61