{"id":5038,"date":"2018-05-14T10:08:12","date_gmt":"2018-05-14T10:08:12","guid":{"rendered":"https:\/\/www.reveantivirus.com\/blog\/?p=5038"},"modified":"2019-08-19T09:25:58","modified_gmt":"2019-08-19T09:25:58","slug":"process-doppelganging","status":"publish","type":"post","link":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging","title":{"rendered":"What is Process Doppelganging &#038; How is it Executed?"},"content":{"rendered":"<p style=\"text-align: justify;\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-5039\" src=\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg\" alt=\"process doppelganging\" width=\"800\" height=\"300\" srcset=\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg 800w, https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging-300x113.jpg 300w, https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging-768x288.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\">Security researchers from enSilo discovered a new code injection attack for Windows OS called \u201cProcess Doppelganging.\u201d Process Doppelganging is similar to Process Hollowing \u2013 a technique utilized by hackers a couple of years back yet now identified by most security software\u2019s. The most recent use of Process Hollowing in the case of Scarab ransomware that spread via 12.5 million emails. Process Doppelganging is a different approach to achieve the same, by abusing Windows NTFS Transactions and an outdated implementation of Windows process loader, which was originally designed for Windows XP but carried throughout all later versions of Windows. The same is done by making fishy things look like legitimate Windows process which can easily bypass security products. The malware can eventually lead to ransom files, monitor keystrokes, or steal confidential information.<\/p>\n<h2 style=\"text-align: justify;\"><strong>How Attack Works?<\/strong><\/h2>\n<p style=\"text-align: justify;\">Doppelganging works by utilizing two distinct features together to mask the loading of a modified executable. By utilizing a feature called Transactional NTFS (TxF) in Windows to make changes to an executable file that will never actu<\/p>\n<p style=\"text-align: justify;\">ally be committed to disk. The <a href=\"https:\/\/www.reveantivirus.com\/en\/computer-security-threats\/what-is-malware\" target=\"_blank\">malware<\/a> had to be either written to disk or run completely from memory, security products developed tools to fight such malware. In case the malware had a file on disk, the file could be scanned.<\/p>\n<p style=\"text-align: justify;\">Software which runs without file is suspicious and could also be detected. With Process Doppelganging, the malicious software can run from a file, but this file will be invisible to security software. The changes made are never written to the disk, so, it\u2019s a file-less attack that cannot be tracked by <strong><a href=\"https:\/\/www.reveantivirus.com\/en\/product\/antivirus\" target=\"_blank\">Antivirus software<\/a><\/strong>. The modified executable is then loaded using the Windows process loading mechanism. The malware process can still be run in such a case. If opened, the file on disk will contain no suspicious content. Moreover, this file can be a well-known, digitally signed application.<\/p>\n<p style=\"text-align: justify;\">A section object is created using the NtCreateSection API from the modified file and the transaction is undone with the Rollback Transaction API. Once this is complete, NtCreateProcessEx is called with the malicious section passed as a parameter and then execution is resumed in the remote process.<\/p>\n<p style=\"text-align: justify;\"><strong>Call chain path:<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong><em>CreateTransaction &#8211;&gt; CreateFileTransacted &#8211;&gt; WriteFile &#8211;&gt; CreateSection &#8211;&gt; NtCreateProcessEx &#8211;&gt; RtlCreateProcessParametersEx &#8211;&gt; VirtualAllocEx &#8211;&gt; WriteProcessMemory &#8211;&gt; NtCreateThreadEx<\/em><\/strong><\/p>\n<p style=\"text-align: justify;\">As we can see, the usage of suspicious API\u2019s such as ReadProcessMemory\/NtReadVirtualMemory, WriteProcessMemory, NtMapViewOfSection and SetThreadContext is less, and the image is stacked by the Windows PE loader rather than written into memory using WPM bringing about a considerably more authentic looking procedure.<\/p>\n<h2 style=\"text-align: justify;\"><strong>Doppelganging into steps:<\/strong><\/h2>\n<ul style=\"text-align: justify;\">\n<li>Transact \u2013 Overwrite legitimate executable with a malicious one<\/li>\n<li>Load \u2013 Load malicious executable<\/li>\n<li>Rollback \u2013 Rollback to original executable<\/li>\n<li>Animate \u2013 Bring the Doppelganger to life<\/li>\n<\/ul>\n<h2 style=\"text-align: justify;\"><strong>WHO DOES THIS AFFECT?<\/strong><\/h2>\n<p style=\"text-align: justify;\">Latest versions of Windows protected with fully-updated AV and NGAV security product attack works on all modern versions of Microsoft Windows operating system, starting from Windows Vista to the latest version of Windows 10. However, a sense of relief is that the attack is pretty hard to perform and requires some knowledge that\u2019s not documented by the researchers.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Process Doppelganging is a different approach to achieve the same, by abusing Windows NTFS Transactions and an outdated implementation of Windows process loader, which was originally designed for Windows XP but carried throughout all later versions of Windows.<\/p>\n","protected":false},"author":15,"featured_media":5039,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[94,203,93,317],"tags":[496,495],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v18.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Learn about Process Doppelganging, how it is executed and who does it affects to increase your knowledge in the cyber security domain.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is Process Doppelganging &amp; How is it Executed?\" \/>\n<meta property=\"og:description\" content=\"Learn about Process Doppelganging, how it is executed and who does it affects to increase your knowledge in the cyber security domain.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging\" \/>\n<meta property=\"og:site_name\" content=\"REVE Antivirus\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/REVE-Antivirus-733117470104716\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-14T10:08:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-08-19T09:25:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:creator\" content=\"@REVEAntivirus\" \/>\n<meta name=\"twitter:site\" content=\"@REVEAntivirus\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Suvarna Trigune\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#website\",\"url\":\"https:\/\/www.reveantivirus.com\/blog\/\",\"name\":\"REVE Antivirus\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.reveantivirus.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg\",\"contentUrl\":\"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg\",\"width\":800,\"height\":300,\"caption\":\"process doppelganging\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#webpage\",\"url\":\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging\",\"name\":\"What is Process Doppelganging & How is it Executed?\",\"isPartOf\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#primaryimage\"},\"datePublished\":\"2018-05-14T10:08:12+00:00\",\"dateModified\":\"2019-08-19T09:25:58+00:00\",\"author\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/28c498c3d53797d74d040454be053d29\"},\"description\":\"Learn about Process Doppelganging, how it is executed and who does it affects to increase your knowledge in the cyber security domain.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.reveantivirus.com\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is Process Doppelganging &#038; How is it Executed?\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/28c498c3d53797d74d040454be053d29\",\"name\":\"Suvarna Trigune\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.reveantivirus.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f465e5338b2d68368a4f146ead3eff44?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f465e5338b2d68368a4f146ead3eff44?s=96&d=mm&r=g\",\"caption\":\"Suvarna Trigune\"},\"description\":\"Suvarna Trigune is malware research engineer who likes to enlighten others about the unknown and little-known facts about cyber security through her blogs.\",\"sameAs\":[\"https:\/\/www.reveantivirus.com\/\"],\"url\":\"https:\/\/www.reveantivirus.com\/blog\/author\/suvarnatrigune\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Learn about Process Doppelganging, how it is executed and who does it affects to increase your knowledge in the cyber security domain.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging","og_locale":"en_US","og_type":"article","og_title":"What is Process Doppelganging & How is it Executed?","og_description":"Learn about Process Doppelganging, how it is executed and who does it affects to increase your knowledge in the cyber security domain.","og_url":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging","og_site_name":"REVE Antivirus","article_publisher":"https:\/\/www.facebook.com\/REVE-Antivirus-733117470104716","article_published_time":"2018-05-14T10:08:12+00:00","article_modified_time":"2019-08-19T09:25:58+00:00","og_image":[{"width":800,"height":300,"url":"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg","type":"image\/jpeg"}],"twitter_card":"summary","twitter_creator":"@REVEAntivirus","twitter_site":"@REVEAntivirus","twitter_misc":{"Written by":"Suvarna Trigune","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.reveantivirus.com\/blog\/#website","url":"https:\/\/www.reveantivirus.com\/blog\/","name":"REVE Antivirus","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.reveantivirus.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#primaryimage","inLanguage":"en-US","url":"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg","contentUrl":"https:\/\/www.reveantivirus.com\/blog\/wp-content\/uploads\/2018\/05\/doppelganging.jpg","width":800,"height":300,"caption":"process doppelganging"},{"@type":"WebPage","@id":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#webpage","url":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging","name":"What is Process Doppelganging & How is it Executed?","isPartOf":{"@id":"https:\/\/www.reveantivirus.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#primaryimage"},"datePublished":"2018-05-14T10:08:12+00:00","dateModified":"2019-08-19T09:25:58+00:00","author":{"@id":"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/28c498c3d53797d74d040454be053d29"},"description":"Learn about Process Doppelganging, how it is executed and who does it affects to increase your knowledge in the cyber security domain.","breadcrumb":{"@id":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.reveantivirus.com\/blog\/en\/process-doppelganging#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.reveantivirus.com\/blog"},{"@type":"ListItem","position":2,"name":"What is Process Doppelganging &#038; How is it Executed?"}]},{"@type":"Person","@id":"https:\/\/www.reveantivirus.com\/blog\/#\/schema\/person\/28c498c3d53797d74d040454be053d29","name":"Suvarna Trigune","image":{"@type":"ImageObject","@id":"https:\/\/www.reveantivirus.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/f465e5338b2d68368a4f146ead3eff44?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f465e5338b2d68368a4f146ead3eff44?s=96&d=mm&r=g","caption":"Suvarna Trigune"},"description":"Suvarna Trigune is malware research engineer who likes to enlighten others about the unknown and little-known facts about cyber security through her blogs.","sameAs":["https:\/\/www.reveantivirus.com\/"],"url":"https:\/\/www.reveantivirus.com\/blog\/author\/suvarnatrigune"}]}},"_links":{"self":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts\/5038"}],"collection":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/comments?post=5038"}],"version-history":[{"count":8,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts\/5038\/revisions"}],"predecessor-version":[{"id":7859,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/posts\/5038\/revisions\/7859"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/media\/5039"}],"wp:attachment":[{"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/media?parent=5038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/categories?post=5038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.reveantivirus.com\/blog\/wp-json\/wp\/v2\/tags?post=5038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}