discovered 03 Aug 2026
project-scorpio
→ View on GitHubProject Scorpio is a sophisticated Windows process injection loader that utilizes techniques such as PPID spoofing, manual DLL mapping, and direct NT syscall execution to stealthily execute staged shellcode within a targeted remote process. Notable features include its ability to fetch payloads from a command and control server using HTTP, spawn a decoy process with a masqueraded parent process, and replace the text section of a mapped DLL without registering it in system tools, thereby minimizing detection risk.