> cat /dev/github | grep security-tools
discovered 03 Aug 2026

KhaosLdr

C ★ 53 via github-topic
→ View on GitHub
KHAØS LOADER is a multi-stage Windows x64 loader that utilizes AES-256-CBC to decrypt and inject donut shellcode into a `rundll32.exe` process spawned under `explorer.exe`, employing advanced evasion techniques such as indirect syscalls with call stack spoofing. Notable features include early-bird APC injection, unhooking capabilities, and robust sandbox evasion mechanisms, which ensure stealthy operation against various security measures. This tool is designed for authorized use only and integrates multiple sophisticated methods to remain undetected during execution.