[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGTG_gIA7gbbVt8ItG0QjwL2UOAqjWVqB7vXxDPikmhk":3},{"article":4,"iocs":26,"watch_terms":30},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":10,"published_at":12,"ingested_at":13,"relevance_score":14,"entities":15,"category_id":16,"category":17,"article_tags":20},"95284ed7-20fa-48ac-9b0e-0494ffa9b5b4","RegPhantom a signed Windows kernel rootkit that turns the registry into a covert execution channe...","regphantom-a-signed-windows-kernel-rootkit-that-turns-the-registry-into-a-covert-2","RegPhantom a signed Windows kernel rootkit that turns the registry into a covert execution channel.\n\nGives the ability to an unprivileged usermode to reflectively load an arbitrary PE into kernel memory, invisible to PsLoadedModuleList and standard driver enumeration tools.\n\nThe","RegPhantom is a signed Windows kernel rootkit that exploits the registry as a covert execution channel, allowing unprivileged usermode processes to reflectively load arbitrary PE files into kernel memory while evading standard driver enumeration and PsLoadedModuleList detection. This sophisticated persistence mechanism demonstrates a novel evasion technique that bypasses traditional kernel monitoring approaches.",null,"https:\u002F\u002Fx.com\u002Fnextronresearch\u002Fstatus\u002F2035006372815757593","2026-03-20T14:51:42+00:00","2026-03-20T15:00:19.767159+00:00",9,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":16,"icon":10,"name":18,"slug":19},"Malware","malware",[21],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[27],{"type":19,"value":28,"context":29},"RegPhantom","Signed Windows kernel rootkit using registry as covert execution channel",[]]