Now You See Me, Now You Don’t - Abusing VBS Enclaves to Create Evasive Malware

No ratings

Presented at BlueHat IL 2025 by

Virtualization Based Security (VBS) is one of the most fascinating security advancements of recent years - the ability to isolate critical components of the OS enabled Microsoft to achieve substantial security improvements with features like Credential Guard and HVCI. One of the more interesting features enabled through VBS is VBS Enclaves - a technology that allows a process to isolate a region of its memory, making it completely inaccessible to other processes, the process itself, and even the kernel. While VBS enclaves can have a wide range of security applications, they can also be very appealing to attackers - running malware in an isolated region, out of the reach of EDRs and security analysts? Sign us up! With this research we set out to explore the concept of enclave malware. We will dive into VBS enclaves while exploring previously undocumented behaviors, describe the different scenarios that can enable attackers to run malicious code inside enclaves, and explore the various techniques enclave malware can utilize. To wrap up, we will introduce “Mirage” - a proof-of-concept memory evasion technique that is based on the “Bring Your Own Vulnerable Enclave” approach.