[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Is It the Beginning of the End For Use-After-Free Exploitation?

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 6 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Tao Yan](https://unit42.paloaltonetworks.com/author/tao-yan/)
  * [Bo Qu](https://unit42.paloaltonetworks.com/author/bo-qu/)
  * [Royce Lu](https://unit42.paloaltonetworks.com/author/royce-lu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:July 16, 2014

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Deferred free](https://unit42.paloaltonetworks.com/tag/deferred-free/)
  * [Internet Explorer](https://unit42.paloaltonetworks.com/tag/internet-explorer/)
  * [Isolated heap](https://unit42.paloaltonetworks.com/tag/isolated-heap/)
  * [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/)
  * [Use after free](https://unit42.paloaltonetworks.com/tag/use-after-free/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/beginning-end-use-free-exploitation/?pdf=download&lg=en&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/beginning-end-use-free-exploitation/?pdf=print&lg=en&_wpnonce=5f0cc26d8b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Is%20It%20the%20Beginning%20of%20the%20End%20For%20Use-After-Free%20Exploitation?&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbeginning-end-use-free-exploitation%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbeginning-end-use-free-exploitation%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbeginning-end-use-free-exploitation%2F&title=Is%20It%20the%20Beginning%20of%20the%20End%20For%20Use-After-Free%20Exploitation? "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbeginning-end-use-free-exploitation%2F&text=Is%20It%20the%20Beginning%20of%20the%20End%20For%20Use-After-Free%20Exploitation? "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbeginning-end-use-free-exploitation%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Is%20It%20the%20Beginning%20of%20the%20End%20For%20Use-After-Free%20Exploitation?%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbeginning-end-use-free-exploitation%2F "Share in Mastodon")
  Use-after-free bugs have affected Internet Explorer for years. In the past year alone, Microsoft patched 122 IE vulnerabilities, the majority of which were use-after-free bugs. This year Microsoft has already patched 126 IE vulnerabilities to date. Of those vulnerabilities, 4 were actively being exploited in the wild. These 4 exploits (CVE-2014-1815, CVE-2014-1776, CVE-2014-0322, CVE-2014-0324) were all based on use-after-free bugs.

To deal with the increasing number of use-after-free bugs and associated exploits, Microsoft introduced a series of new control mechanisms in the most recent Internet Explorer patches. In June, Microsoft introduced a new *isolated heap* mechanism to solve the usage issue of use-after-free exploitation. They followed that up In July by implementing a *deferred free* method to solve the freeing issue of use-after-free bugs.

The main concept of an *isolated heap* is simple. It allocates a dedicated heap for select critical objects to use that is separate from other heaps that a user can directly access. The heap block will not be occupied by user-controlled data after the critical objects are freed. This mechanism prevents precise control of the data of a freed object from further exploitation.  
.text:63DA6814 ; int \_\_stdcall \_MemIsolatedAlloc(SIZE\_T dwBytes) .text:63DA6814 \_\_MemIsolatedAlloc@4 proc near .text:63DA6814 dwBytes = dword ptr 8 .text:63DA6814 .text:63DA6814 mov edi, edi .text:63DA6816 push ebp .text:63DA6817 mov ebp, esp .text:63DA6819 push \[ebp+dwBytes\] ; dwBytes .text:63DA681C push 0 ; dwFlags .text:63DA681E push \_g\_hIsolatedHeap ; hHeap .text:63DA6824 call ds:\_\_imp\_\_HeapAlloc@12 ; HeapAlloc(x,x,x) .text:63DA682A pop ebp .text:63DA682B retn 4 .text:63DA682B \_\_MemIsolatedAlloc@4 endp

|----------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 | .text:63DA6814 ; int \_\_stdcall \_MemIsolatedAlloc(SIZE\_T dwBytes) .text:63DA6814 \_\_MemIsolatedAlloc@4 proc near .text:63DA6814 dwBytes = dword ptr 8 .text:63DA6814 .text:63DA6814 mov edi, edi .text:63DA6816 push ebp .text:63DA6817 mov ebp, esp .text:63DA6819 push \[ebp+dwBytes\] ; dwBytes .text:63DA681C push 0 ; dwFlags .text:63DA681E push \_g\_hIsolatedHeap ; hHeap .text:63DA6824 call ds:\_\_imp\_\_HeapAlloc@12 ; HeapAlloc(x,x,x) .text:63DA682A pop ebp .text:63DA682B retn 4 .text:63DA682B \_\_MemIsolatedAlloc@4 endp |

Figure 1. \_g\_hIsolatedHeap handle used for isolated heap

The *isolated heap* was applied to many but not all internal objects, leaving some still vulnerable. To address this, Microsoft introduced another protection method of *deferred free* named **ProtectedFree** . They encapsulate this method and apply it to almost every object in mshtml.dll. In IE9, for example, it has been applied to every object through **MemoryProtection::HeapFree** as shown in figure 2.

![figure 2](http://blog.paloaltonetworks.com/wp-content/uploads/2014/07/figure-2-500x313.png)

Figure 2. References of MemoryProtection::HeapFree

The main idea of this protection mechanism is to delay the freeing action so that the intruder is unable to determine when they can occupy the freed object using controlled data. In this new patch, every time Internet Explorer tries to free an object, it is not freed immediately. Instead, the block to be freed is marked and filled with 0x00 data and added to a pool. When the size of the pool hits a predefined threshold, which is currently 100k (0x186A0 as highlighted in figure 3), it performs the real freeing operation (**ReclaimUnmarkedBlocks**).  
void MemoryProtection::CMemoryProtector::ProtectedFree(void \*hProcessHeap, void\* lpMem, DWORD a, void \*b) { ... v\_lpMem = lpMem; v\_ProcessHeap = hProcessHeap; if ( !lpMem ) return; if ( MemoryProtection::CMemoryProtector::tlsSlotForInstance == -1 || (st\_ProtecFreeManageHeap = TlsGetValue(MemoryProtection::CMemoryProtector::tlsSlotForInstance)) == 0) { HeapFree(v\_ProcessHeap, 0, (LPVOID)lpMem); return; } if ( \*((\_DWORD \*)v\_ProcessHeapBase + 2) \&\&(\*((\_DWORD \*)st\_ProtecFreeManageHeap+ 1) \>= 0x186A0 || \*((\_BYTE \*)st\_ProtecFreeManageHeap + 20))) { MemoryProtection::CMemoryProtector::MarkBlocks(st\_ProtecFreeManageHeap, \&v17); MemoryProtection::CMemoryProtector::ReclaimUnmarkedBlocks(st\_ProtecFreeManageHeap); } ... }

|-------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 | void MemoryProtection::CMemoryProtector::ProtectedFree(void \*hProcessHeap, void\* lpMem, DWORD a, void \*b) { ... v\_lpMem = lpMem; v\_ProcessHeap = hProcessHeap; if ( !lpMem ) return; if ( MemoryProtection::CMemoryProtector::tlsSlotForInstance == -1 || (st\_ProtecFreeManageHeap = TlsGetValue(MemoryProtection::CMemoryProtector::tlsSlotForInstance)) == 0) { HeapFree(v\_ProcessHeap, 0, (LPVOID)lpMem); return; } if ( \*((\_DWORD \*)v\_ProcessHeapBase + 2) \&\&(\*((\_DWORD \*)st\_ProtecFreeManageHeap+ 1) \>= 0x186A0 || \*((\_BYTE \*)st\_ProtecFreeManageHeap + 20))) { MemoryProtection::CMemoryProtector::MarkBlocks(st\_ProtecFreeManageHeap, \&v17); MemoryProtection::CMemoryProtector::ReclaimUnmarkedBlocks(st\_ProtecFreeManageHeap); } ... } |

Figure 3. C++ style pseudo code of ProtectedFree function

Microsoft stores the to-be-freed blocks in a structure called **st\_ProtecFreeManageHeap** . This structure is created in the function **MemoryProtection::CMemoryProtector::ProtectCurrentThread** and is used to manage deferred free heap blocks. Figure 4 shows an example of the structure in memory.  
0:007\> dc 0e6f6fe0 0e6f6fe0 0e829000 00008bfa 000000fe 00000400 ................ 0e6f6ff0 c0c0c000 c0c0c000 0ca70000 0ca6c8e8 ................ Red: current heap block address Yellow: current heap block size Blue: current heap block counts Green: heap block capacity Gray: HeapBase 0:007\> !heap -p -a 0e6f6fe0 address 0e6f6fe0 found in \_DPH\_HEAP\_ROOT @ 61000 in busy allocation (DPH\_HEAP\_BLOCK: UserAddr UserSize VirtAddr VirtSize) e463888: e6f6fe0 20 e6f6000 2000 6ca48e89 verifier!AVrfDebugPageHeapAllocate+0x00000229 76f55ede ntdll!RtlDebugAllocateHeap+0x00000030 76f1a40a ntdll!RtlpAllocateHeap+0x000000c4 76ee5ae0 ntdll!RtlAllocateHeap+0x0000023a 660120b0 MSHTML!MemoryProtection::CMemoryProtector::ProtectCurrentThread+0x00000062 65ea9138 MSHTML!GlobalWndProc+0x00000015 7596c4e7 user32!InternalCallWinProc+0x00000023 75965f9f user32!UserCallWinProcCheckWow+0x000000e0 75964f0e user32!DispatchClientMessage+0x000000da 7595e98a user32!\_\_fnINLPCREATESTRUCT+0x0000008b 76ed702e ntdll!KiUserCallbackDispatcher+0x0000002e 7595ec54 user32!\_CreateWindowEx+0x00000201 7595ecaf user32!CreateWindowExW+0x00000033 6c4f3985 IEShims!NS\_HangResistanceInternal::APIHook\_CreateWindowExW+0x00000081 660123e3 MSHTML!InitGlobalWindow+0x00000098 ... .text:63752097; CODE XREF: MemoryProtection::CMemoryProtector::ProtectCurrentThread(void)+169054j .text:63752097 test edi, edi .text:63752099 jz loc\_635E90E1 .text:6375209F push ebx .text:637520A0 push 20h ; dwBytes .text:637520A2 xor ebx, ebx .text:637520A4 push ebx ; dwFlags .text:637520A5 push \_g\_hProcessHeap ; hHeap .text:637520AB call \_HeapAlloc@12 ; HeapAlloc(x,x,x) .text:637520B0 mov esi, eax .text:637520B2 test esi, esi .text:637520B4 jz short loc\_63752101 .text:637520B6 mov \[esi\], ebx .text:637520B8 mov \[esi+4\], ebx .text:637520BB mov \[esi+8\], ebx .text:637520BE mov \[esi+0Ch\], ebx .text:637520C1 mov \[esi+10h\], bl .text:637520C4 mov \[esi+14h\], bl .text:637520C7 mov \[esi+18h\], ebx .text:637520CA mov \[esi+1Ch\], ebx

|----------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 | 0:007\> dc 0e6f6fe0 0e6f6fe0 0e829000 00008bfa 000000fe 00000400 ................ 0e6f6ff0 c0c0c000 c0c0c000 0ca70000 0ca6c8e8 ................ Red: current heap block address Yellow: current heap block size Blue: current heap block counts Green: heap block capacity Gray: HeapBase 0:007\> !heap -p -a 0e6f6fe0 address 0e6f6fe0 found in \_DPH\_HEAP\_ROOT @ 61000 in busy allocation (DPH\_HEAP\_BLOCK: UserAddr UserSize VirtAddr VirtSize) e463888: e6f6fe0 20 e6f6000 2000 6ca48e89 verifier!AVrfDebugPageHeapAllocate+0x00000229 76f55ede ntdll!RtlDebugAllocateHeap+0x00000030 76f1a40a ntdll!RtlpAllocateHeap+0x000000c4 76ee5ae0 ntdll!RtlAllocateHeap+0x0000023a 660120b0 MSHTML!MemoryProtection::CMemoryProtector::ProtectCurrentThread+0x00000062 65ea9138 MSHTML!GlobalWndProc+0x00000015 7596c4e7 user32!InternalCallWinProc+0x00000023 75965f9f user32!UserCallWinProcCheckWow+0x000000e0 75964f0e user32!DispatchClientMessage+0x000000da 7595e98a user32!\_\_fnINLPCREATESTRUCT+0x0000008b 76ed702e ntdll!KiUserCallbackDispatcher+0x0000002e 7595ec54 user32!\_CreateWindowEx+0x00000201 7595ecaf user32!CreateWindowExW+0x00000033 6c4f3985 IEShims!NS\_HangResistanceInternal::APIHook\_CreateWindowExW+0x00000081 660123e3 MSHTML!InitGlobalWindow+0x00000098 ... .text:63752097; CODE XREF: MemoryProtection::CMemoryProtector::ProtectCurrentThread(void)+169054j .text:63752097 test edi, edi .text:63752099 jz loc\_635E90E1 .text:6375209F push ebx .text:637520A0 push 20h ; dwBytes .text:637520A2 xor ebx, ebx .text:637520A4 push ebx ; dwFlags .text:637520A5 push \_g\_hProcessHeap ; hHeap .text:637520AB call \_HeapAlloc@12 ; HeapAlloc(x,x,x) .text:637520B0 mov esi, eax .text:637520B2 test esi, esi .text:637520B4 jz short loc\_63752101 .text:637520B6 mov \[esi\], ebx .text:637520B8 mov \[esi+4\], ebx .text:637520BB mov \[esi+8\], ebx .text:637520BE mov \[esi+0Ch\], ebx .text:637520C1 mov \[esi+10h\], bl .text:637520C4 mov \[esi+14h\], bl .text:637520C7 mov \[esi+18h\], ebx .text:637520CA mov \[esi+1Ch\], ebx |

Figure 4. st\_ProtecFreeManageHeap

Figure 5 provides an alternate view of the structure in a C style code block.  
typedef struct SBlockDescriptor{ LPVOID mem; // if(!(mem\&2)) mem from ProcessHeap; Else from IsolateHeap; DWORd MemSize; }; typedef struct st\_ProtecFreeManageHeap{ PVOID buffer; //point to an array of SBlockDescriptor DWORD TotalMemorySize; DWORD CurrentNumOfDescriptor; DWORD MaxNumOfDescriptor; BOOL bQsorted; //\*((BYTE\*)this+16) ... }

|-------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | typedef struct SBlockDescriptor{ LPVOID mem; // if(!(mem\&2)) mem from ProcessHeap; Else from IsolateHeap; DWORd MemSize; }; typedef struct st\_ProtecFreeManageHeap{ PVOID buffer; //point to an array of SBlockDescriptor DWORD TotalMemorySize; DWORD CurrentNumOfDescriptor; DWORD MaxNumOfDescriptor; BOOL bQsorted; //\*((BYTE\*)this+16) ... } |

Figure 5. C style code of st\_ProtecFreeManageHeap

If we were able to make the size of the current heap block in this structure larger than the threshold of 0x186A0 bytes and trigger **CMemoryProtector::ProtectedFree**, it is still possible to force a true freeing action and occupy the freed object with other data as we show in the following piece of javascript code in figure 6.  
\<html\> \<head\> \</head\> \<body\> \<script\> alert("we'll create a UAF using windbg"); arr = new Array(); arr2 = new Array(); //create anchor Element var anchor = document.createElement('a'); //arr\[0\] = anchor; //arr2\[0\] = anchor; document.body.appendChild(anchor); //now anchor refcount is 2. alert("use windbg attach IE process and make the anchor Element's refcount decreased by 1"); //arr\[0\] = ""; document.body.removeChild(anchor); alert("anchor Element has been protected free'd"); //fill the "current heap block size" in v\_ProtectFreeManageHeap structure and make it bigger than 0x186A0 for(var i=0; i\<0x3f0; i++){ arr\[i\] = document.createElement('a'); } //trigger "CMemoryProtector::ProtectedFree" once again for(var i=0; i\<0x3f0; i++){ arr\[i\] = ""; } CollectGarbage(); alert("ForceFree\_done") alert("reuse"); alert(anchor.title); \</script\>

|-------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 | \<html\> \<head\> \</head\> \<body\> \<script\> alert("we'll create a UAF using windbg"); arr = new Array(); arr2 = new Array(); //create anchor Element var anchor = document.createElement('a'); //arr\[0\] = anchor; //arr2\[0\] = anchor; document.body.appendChild(anchor); //now anchor refcount is 2. alert("use windbg attach IE process and make the anchor Element's refcount decreased by 1"); //arr\[0\] = ""; document.body.removeChild(anchor); alert("anchor Element has been protected free'd"); //fill the "current heap block size" in v\_ProtectFreeManageHeap structure and make it bigger than 0x186A0 for(var i=0; i\<0x3f0; i++){ arr\[i\] = document.createElement('a'); } //trigger "CMemoryProtector::ProtectedFree" once again for(var i=0; i\<0x3f0; i++){ arr\[i\] = ""; } CollectGarbage(); alert("ForceFree\_done") alert("reuse"); alert(anchor.title); \</script\> |

Figure 6. Javascript proof of concept to force freeing

When creating the anchor element, the debug logs are shown in figure 7. The address of the anchor element is 0x0c3b3f98.  
0:005\> dc 0c3b3f98 0c3b3f98 650acb88 00000002 00000002 00000008 ...e............ 0c3b3fa8 65c87088 00000000 0ba65750 0c3b5fa0 .p.e....PW...\_;. 0c3b3fb8 00000002 02040000 90000e00 00060004 ................ 0c3b3fc8 0c39dbd8 650acb64 0c3b3fcc 00000000 ..9.d..e.?;..... 0c3b3fd8 00000000 00000000 00000000 00000000 ................ 0c3b3fe8 00000000 00000000 00000000 00000000 ................ 0c3b3ff8 00000001 d0d0d0d0 ???????? ???????? ........???????? 0:005\> !heap -p -a 0c3b3f98 address 0c3b3f98 found in \_DPH\_HEAP\_ROOT @ c381000 in busy allocation (DPH\_HEAP\_BLOCK: UserAddr UserSize VirtAddr VirtSize) c381ac0: c3b3f98 64 c3b3000 2000 MSHTML!CAnchorElement::\`vftable' 6dae8e89 verifier!AVrfDebugPageHeapAllocate+0x00000229 76f55ede ntdll!RtlDebugAllocateHeap+0x00000030 76f1a40a ntdll!RtlpAllocateHeap+0x000000c4 76ee5ae0 ntdll!RtlAllocateHeap+0x0000023a 650aca58 MSHTML!CAnchorElement::CreateElement+0x00000018 64e98e84 MSHTML!CreateElement+0x00000061 64f0d1dd MSHTML!CMarkup::CreateElement+0x00000191 64f0d35b MSHTML!CDocument::CreateElementHelper+0x000000fb 64f0d432 MSHTML!CDocument::Var\_createElement+0x00000046 64f0d3cf MSHTML!CFastDOM::CDocument::Trampoline\_createElement+0x00000044 681342b4 jscript9!Js::JavascriptExternalFunction::ExternalFunctionThunk+0x00000165 68132ea4 jscript9!Js::InterpreterStackFrame::Process+0x00000ba8 6813351a jscript9!Js::InterpreterStackFrame::InterpreterThunk\<1\>+0x000001e8

|-------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 | 0:005\> dc 0c3b3f98 0c3b3f98 650acb88 00000002 00000002 00000008 ...e............ 0c3b3fa8 65c87088 00000000 0ba65750 0c3b5fa0 .p.e....PW...\_;. 0c3b3fb8 00000002 02040000 90000e00 00060004 ................ 0c3b3fc8 0c39dbd8 650acb64 0c3b3fcc 00000000 ..9.d..e.?;..... 0c3b3fd8 00000000 00000000 00000000 00000000 ................ 0c3b3fe8 00000000 00000000 00000000 00000000 ................ 0c3b3ff8 00000001 d0d0d0d0 ???????? ???????? ........???????? 0:005\> !heap -p -a 0c3b3f98 address 0c3b3f98 found in \_DPH\_HEAP\_ROOT @ c381000 in busy allocation (DPH\_HEAP\_BLOCK: UserAddr UserSize VirtAddr VirtSize) c381ac0: c3b3f98 64 c3b3000 2000 MSHTML!CAnchorElement::\`vftable' 6dae8e89 verifier!AVrfDebugPageHeapAllocate+0x00000229 76f55ede ntdll!RtlDebugAllocateHeap+0x00000030 76f1a40a ntdll!RtlpAllocateHeap+0x000000c4 76ee5ae0 ntdll!RtlAllocateHeap+0x0000023a 650aca58 MSHTML!CAnchorElement::CreateElement+0x00000018 64e98e84 MSHTML!CreateElement+0x00000061 64f0d1dd MSHTML!CMarkup::CreateElement+0x00000191 64f0d35b MSHTML!CDocument::CreateElementHelper+0x000000fb 64f0d432 MSHTML!CDocument::Var\_createElement+0x00000046 64f0d3cf MSHTML!CFastDOM::CDocument::Trampoline\_createElement+0x00000044 681342b4 jscript9!Js::JavascriptExternalFunction::ExternalFunctionThunk+0x00000165 68132ea4 jscript9!Js::InterpreterStackFrame::Process+0x00000ba8 6813351a jscript9!Js::InterpreterStackFrame::InterpreterThunk\<1\>+0x000001e8 |

Figure 7: Before free

We then manually decrease the reference number, so the **CMemoryProtector::ProtectedFree function will fill the block with 0's, but the object is still not freed.**  
Set anchor 0x00 0c3b3f98 00000000 00000000 00000000 00000000 0c3b3fa8 00000000 00000000 00000000 00000000 0c3b3fb8 00000000 00000000 00000000 00000000 0c3b3fc8 00000000 00000000 00000000 00000000 0c3b3fd8 00000000 00000000 00000000 00000000 0c3b3fe8 00000000 00000000 00000000 00000000 0c3b3ff8 00000000 d0d0d0d0 ???????? ????????

|-----------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | Set anchor 0x00 0c3b3f98 00000000 00000000 00000000 00000000 0c3b3fa8 00000000 00000000 00000000 00000000 0c3b3fb8 00000000 00000000 00000000 00000000 0c3b3fc8 00000000 00000000 00000000 00000000 0c3b3fd8 00000000 00000000 00000000 00000000 0c3b3fe8 00000000 00000000 00000000 00000000 0c3b3ff8 00000000 d0d0d0d0 ???????? ???????? |

Figure 8: decrease the reference number, not yet freed

Finally we make the size of the **CMemoryProtector::ProtectedFree** management structure larger than 0x186a0 forcing the freeing operation.  
0:007\> dc eax 0dde6fe0 0e109000 000186b2 000003a5 00000400 ................ 0dde6ff0 c0c0c000 c0c0c000 0c380000 0c37c590 ..........8...7.

|-------|--------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | 0:007\> dc eax 0dde6fe0 0e109000 000186b2 000003a5 00000400 ................ 0dde6ff0 c0c0c000 c0c0c000 0c380000 0c37c590 ..........8...7. |

Figure 9: field "TotalMemorySize" of st\_ProtecFreeManageHeap is greater than threshold

The anchor element is now actually freed as shown in figure 10.  
0:006\> !heap -p -a 0c3b3f98 address 0c3b3f98 found in \_DPH\_HEAP\_ROOT @ c381000 in free-ed allocation ( DPH\_HEAP\_BLOCK: VirtAddr VirtSize) c381ac0: c3b3000 2000 6dae90b2 verifier!AVrfDebugPageHeapFree+0x000000c2 76f566ac ntdll!RtlDebugFreeHeap+0x0000002f 76f1a13e ntdll!RtlpFreeHeap+0x0000005d 76ee65a6 ntdll!RtlFreeHeap+0x00000142 76dfc3d4 kernel32!HeapFree+0x00000014 64e56dc3 MSHTML!MemoryProtection::CMemoryProtector::ReclaimUnmarkedBlocks+0x00000046 652468b0 MSHTML!CAnchorElement::\`scalar deleting destructor'+0x0000008c 64e59602 MSHTML!CElement::PrivateRelease+0x000001b3 651cec6a MSHTML!CBase::JSBind\_Release+0x00000016 681ab380 jscript9!Js::CustomExternalObject::Dispose+0x00000017 681aaf97 jscript9!SmallFinalizableHeapBlock::DisposeObjects+0x00000067 681ab17e jscript9!HeapInfo::DisposeObjects+0x000000b0 681ab078 jscript9!Recycler::DisposeObjects+0x00000049 681ab027 jscript9!Recycler::FinishDisposeObjects+0x0000001a 681a7a34 jscript9!DefaultRecyclerCollectionWrapper::ExecuteRecyclerCollectionFunction+0x00000017 681a7a06 jscript9!ThreadContext::ExecuteRecyclerCollectionFunctionCommon+0x0000003b 681a798c jscript9!ThreadContext::ExecuteRecyclerCollectionFunction+0x000000ad 681a80ef jscript9!Recycler::DoCollectWrapped+0x0000005a 682d8748 jscript9!Recycler::Collect\<-1073475584\>+0x0000004b 6813302e jscript9!Js::InterpreterStackFrame::Process+0x00001e54 6813351a jscript9!Js::InterpreterStackFrame::InterpreterThunk\<1\>+0x000001e8

|----------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 | 0:006\> !heap -p -a 0c3b3f98 address 0c3b3f98 found in \_DPH\_HEAP\_ROOT @ c381000 in free-ed allocation ( DPH\_HEAP\_BLOCK: VirtAddr VirtSize) c381ac0: c3b3000 2000 6dae90b2 verifier!AVrfDebugPageHeapFree+0x000000c2 76f566ac ntdll!RtlDebugFreeHeap+0x0000002f 76f1a13e ntdll!RtlpFreeHeap+0x0000005d 76ee65a6 ntdll!RtlFreeHeap+0x00000142 76dfc3d4 kernel32!HeapFree+0x00000014 64e56dc3 MSHTML!MemoryProtection::CMemoryProtector::ReclaimUnmarkedBlocks+0x00000046 652468b0 MSHTML!CAnchorElement::\`scalar deleting destructor'+0x0000008c 64e59602 MSHTML!CElement::PrivateRelease+0x000001b3 651cec6a MSHTML!CBase::JSBind\_Release+0x00000016 681ab380 jscript9!Js::CustomExternalObject::Dispose+0x00000017 681aaf97 jscript9!SmallFinalizableHeapBlock::DisposeObjects+0x00000067 681ab17e jscript9!HeapInfo::DisposeObjects+0x000000b0 681ab078 jscript9!Recycler::DisposeObjects+0x00000049 681ab027 jscript9!Recycler::FinishDisposeObjects+0x0000001a 681a7a34 jscript9!DefaultRecyclerCollectionWrapper::ExecuteRecyclerCollectionFunction+0x00000017 681a7a06 jscript9!ThreadContext::ExecuteRecyclerCollectionFunctionCommon+0x0000003b 681a798c jscript9!ThreadContext::ExecuteRecyclerCollectionFunction+0x000000ad 681a80ef jscript9!Recycler::DoCollectWrapped+0x0000005a 682d8748 jscript9!Recycler::Collect\<-1073475584\>+0x0000004b 6813302e jscript9!Js::InterpreterStackFrame::Process+0x00001e54 6813351a jscript9!Js::InterpreterStackFrame::InterpreterThunk\<1\>+0x000001e8 |

Figure 10: object is in the free list now

From a researchers' point of view, deferred free created a few problems, one of the major ones being that the page heap feature may not work correctly. Page heap is a useful feature for debugging. When page heap is turned on, the system allows only one object in one memory page. Once this object is freed the whole page is marked as invalid. So the next time IE tries to access a freed object an invalid address exception would be raised. This mechanism is extremely helpful when researchers are trying to find use-after-free bugs.

With the introduction of the deferred free patch the object is no longer truly freed, so the page still exists. In this situation the researcher is no longer able to determine whether a use-after-free behavior has occurred because no exception would be thrown out. To reduce the impact of the deferred free patch, a research may consider patching the mshtml.dll in memory. For example, you can call **MemoryProtection::CMemoryProtector::UnprotectProcess** before you perform any fuzzing tasks.

The recent patches and introduction of *isolated heap* and *deferred free* are strong signs that Microsoft plans to address the fundamentals of use-after-free exploitation in a preventative manner rather than to passively patch the vulnerabilities as they are discovered. From the results of our research, applications of such methods can effectively stop unpatched use-after-free attacks. It can also make the exploitations of heap overflows or type confusion bugs significantly more difficult. But this is not the end.

For the foreseeable future, Microsoft may introduce more defensive mechanisms against use-after-free bugs or even heap fengshui to reduce the risk of being exploited. Could it be game over for use-after-free exploitation, or it is just the beginning of another cat and mouse game? Time will tell.
Back to top

### Tags

* [Deferred free](https://unit42.paloaltonetworks.com/tag/deferred-free/ "Deferred free")
* [Internet Explorer](https://unit42.paloaltonetworks.com/tag/internet-explorer/ "Internet Explorer")
* [Isolated heap](https://unit42.paloaltonetworks.com/tag/isolated-heap/ "isolated heap")
* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")
* [Use after free](https://unit42.paloaltonetworks.com/tag/use-after-free/ "use after free")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Iptables Backdoor: Even Linux Is At Risk of Intrusion](https://unit42.paloaltonetworks.com/iptables-backdoor-even-linux-risk-intrusion/ "Iptables Backdoor: Even Linux Is At Risk of Intrusion")

### Related Articles

* [How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "article - table of contents")
* [Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools](https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/ "article - table of contents")
* [Microsoft WSUS Remote Code Execution (CVE-2025-59287) Actively Exploited in the Wild (Updated November 3)](https://unit42.paloaltonetworks.com/microsoft-cve-2025-59287/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
