
Overview
We’d like to introduce a new Zero-Tay technique for injecting code and maintaining persistency against common advanced attacker toolkits dubbed TripleAgent. We discovered this by ourselves in our very advanced labs, and are in the process of registering a new vanity domain as we speak. TripleAgent can exploit:
- Every toolkit version
- Every toolkit architecture (x86 and x64)
- Every toolkit user (RED / PURPLE / APT / NATION STATE / etc.)
- Every toolkit process (including PoC, GTFO, PoC||GTFO, METASPLOIT, UNICORN)
TripleAgent exploits a fundamental flaw in the design of commonly used advanced attacker toolkits, and therefore cannot be patched.
