[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNIbKa9kTiwGvhHiJ_4k6NZoYKa-YMPt9IqQnDpT4Y5Q":3},{"article":4,"iocs":26,"watch_terms":30},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":10,"published_at":12,"ingested_at":13,"relevance_score":14,"entities":15,"category_id":16,"category":17,"article_tags":20},"383445a7-7b58-432a-ad17-5faba086009f","RegPhantom a signed Windows kernel rootkit that turns the registry into a covert execution channe...","regphantom-a-signed-windows-kernel-rootkit-that-turns-the-registry-into-a-covert","RegPhantom a signed Windows kernel rootkit that turns the registry into a covert execution channel.\n\nGives the ability to an unprivileged usermode to reflectively load an arbitrary PE into kernel memory, invisible to PsLoadedModuleList and standard driver enumeration tools.\n\nThe https:\u002F\u002Ft.co\u002FPMXfAc9LME","RegPhantom is a signed Windows kernel rootkit that exploits the registry as a covert execution channel, allowing unprivileged usermode processes to reflectively load arbitrary PE files into kernel memory while evading standard driver enumeration tools and PsLoadedModuleList detection.",null,"https:\u002F\u002Fx.com\u002Fnextronresearch\u002Fstatus\u002F2035006494865752415","2026-03-20T14:52:11+00:00","2026-03-20T15:00:19.767159+00:00",9,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":16,"icon":10,"name":18,"slug":19},"Malware","malware",[21],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[27],{"type":19,"value":28,"context":29},"RegPhantom","Signed Windows kernel rootkit using registry as covert execution channel",[]]