BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//speaker//PQNFD8
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-AGFMRW@cfp.romhack.io
DTSTART;TZID=CET:20261002T143000
DTEND;TZID=CET:20261002T151000
DESCRIPTION:As EDR products continue to improve their ability to detect mal
 icious behavior\, malware developers are increasingly adding layers of com
 plexity in an attempt to evade detection.\n\nOne of the most challenging o
 perations to perform under the radar remains code injection. This seemingl
 y unavoidable step is associated with numerous indicators of compromise\, 
 ranging from well-known Windows API calls to uncommon memory permissions o
 r suspicious execution flows.\n\nTo address this challenge\, we revisit th
 e decade-old technique of *code caves*: unused memory locations within leg
 itimate binaries that can be repurposed to host and execute malicious code
 . By extending the concept to include *dead code* and embracing position-i
 ndependent payload development we show that it is not only possible to go 
 beyond classic code cave limitations\, but also eliminate the need for cod
 e injection altogether.\n\nThrough practical demonstrations\, we will show
  how it is possible to automate the discovery and weaponization of dead co
 de in legitimate binaries. This proof of concept advocates a renewed philo
 sophy of malware development\, emphasizing simplicity and minimalism rathe
 r than increasingly complex evasion chains.\n\nFinally\, we discuss import
 ant defensive implications of this work : if attackers can increasingly av
 oid traditional injection artifacts\, detection strategies should focus le
 ss on how code reached execution and more on what that code ultimately doe
 s.
DTSTAMP:20260921T191250Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Stop Injecting\, Start Blending: A KISS Approach to Malware Develop
 ment - Julien Bedel
URL:https://cfp.romhack.io/romhack-camp-2026/talk/AGFMRW/
END:VEVENT
END:VCALENDAR
