-
Thread Hijacking Iceberg: Deep Dive into Phantom Call & RtlRemoteCall
Phantom Call What is phantom call? It is a combination of thread hijacking and calling interesting APIs on a newly crafted stack in the context of hijacked thread in a more stable way. A quick summary of the technique X64 stack alignment Our target Straight to business, lets take a look at our target. A…