Black Hat USA 2026  ·  By Invitation Only

Live Adversary
Emulation

Morphisec CyberRange  ·  Real Threats. Real Payloads. Real Prevention.

Three attack chains built from real ransomware TTPs, detonated against leading EDRs, then intercepted by Morphisec. Every payload is custom-built, polymorphic, and invisible to VirusTotal.

August 4–6, 2026
Mandalay Bay, Las Vegas
NDA Required
Limited to 8 Sessions / Day
0
Live Attack Scenarios
0
VirusTotal Detections
0
Morphisec Block Rate
0
EDR Detections
Threat Intelligence

The Collapse of
Exploit Lead Time

The window from disclosed weakness to working exploit has collapsed from years to hours. Detect-patch-respond can't keep pace.

AI-class models don't introduce new attack categories. They collapse the time to build one. Fuzzing at scale, PoC generation in minutes, weaponization before any CVE is assigned. Many of these flaws never get reported. They get sold. You end up defending against exploits for vulnerabilities that will never be disclosed.

The Morphisec Answer

Morphisec's AMTD morphs memory at runtime. A memory-based exploit, disclosed or not, still has to find its target where the OS normally places it. We've already moved it. Speed and novelty stop being attacker advantages when the attack surface itself is gone.

Median Time-to-Exploit  ·  CVE Disclosure → Confirmed In-the-Wild Use
2018
2.3 years
2020
~190 days
2022
~42 days
2024
~5 days
2026
18 hours
2027
<1 hour (proj.)
Source: zerodayclock.com · 3,500+ confirmed-exploited CVEs · CISA KEV + VulnCheck KEV
⚠️

Signatures needed to stop a novel or undisclosed exploit: zero. AMTD randomizes the attack surface at runtime. The same defense that stops the known exploit stops the unknown one.

Live Attack Chain

Four Stages. One Defense.

Every stage is drawn from active 2025–2026 campaigns. All binaries are rebuilt per session with unique hashes. Nothing on VirusTotal.

Initial Access
ClickFix social engineering lure. Victim runs a command from a spoofed portal.
T1566 · T1059
BYOVD Bypass
Signed vulnerable driver strips EDR kernel callbacks. Protection goes blind.
T1068 · T1562
Data Exfil
Custom binary. No PowerShell, no rclone. HTTPS traffic blends with normal cloud sync.
T1048 · T1083
Ransomware
ChaCha20-Poly1305 per-file, RSA-4096 wrapping, intermittent encryption pattern
T1486 · T1027
Morphisec
Memory execution layer intercepts every stage. Deterministic. No signatures.
100% BLOCKED
Attack Scenarios

Three Scenarios. Three EDR Failures.

Each scenario is modeled on real threat actor campaigns from 2025–2026. Detailed attack chain briefs sent after registration.

1
Social Engineering → Data Theft
Silent Exfiltration
ClickFix lureCustom Go binaryNo PowerShellHTTPS exfil

Data theft modeled on infostealer and extortion-only TTPs. ClickFix delivery, no attachments, no exploit. Custom binary uploads over HTTPS. Looks like normal cloud sync.

✕ EDR
Unique hash, legitimate traffic, clean parent chain
✓ Morphisec
Execution intercepted at memory layer before enumeration
T1566T1059T1048T1083
2
Social Engineering → Ransomware
Akira-Style Encryption
ChaCha20-Poly1305RSA-4096IntermittentFull EDR evasion

Full ransomware simulation modeled on Akira group TTPs. Intermittent encryption, per-file cryptography, RSA key wrapping. Built to defeat every major EDR.

✕ EDR
Hash unknown, I/O below threshold, entropy inconsistent
✓ Morphisec
Key captured in memory. Blocked pre-execution in Protect mode.
T1566T1059T1486T1490T1027
3
LOLBin → RMM Pivot
Legitimate Tool Abuse
Signed RMM agentPersistent C2Remote exfilRansomware via RMM

The most dangerous pattern in use today: a commercially signed RMM tool as a stealthy C2 channel. Used by Black Basta, Scattered Spider, and BianLian in 2025–2026.

✕ EDR
RMM is signed and whitelisted. Payloads arrive through a trusted channel.
✓ Morphisec
Downstream payloads caught at execution regardless of delivery method
T1219T1566T1059T1048T1486
Defense Architecture

Where We Intercept

Three interception points. No signatures. No behavioral rules. No scanning.

Before
Pre-Attack Surface
AMTD: Runtime Memory Morphing
Attacker Maps
0x00401000
0x00402C40
0x7FFE0000
0x00403800
0x7FFE1428
amtd
Morphisec Serves
0x3A91C000
0xB20F4C40
0x6E1A0000
0x9C23B800
0x1F890428
Exploit finds only decoys. Fails deterministically.
  • Memory morphed at runtime. No static target for the exploit.
  • Works against undisclosed 0-days. No CVE needed.
  • Exfil tools blocked before execution
No CVE Required · No Patch Window
During
Active Execution
Execution Interception + ETW / AMSI Guard
explorer.exe
powershell.exe
payload.exe
[4095]ETW patch attempt
[4096]AMSI bypass BLOCKED
[4097]Detonation BLOCKED
[4098]Event → SIEM ✓
EDR keeps its sight. Stack stays effective.
  • ETW + AMSI tampering caught in memory
  • AI agent hijack stopped at execution layer
  • Deterministic events feed high-fidelity SIEM alerts
ETW + AMSI Protected · Stack Stays Effective
After
Encryption Event
In-Memory Symmetric Key Capture
3F A2 9C B1
E7 44 0F 2D
Encrypted
AES-256
captured
FILE.docx
RESTORED
Decrypted
Akira · BlackCat · LockBit · Cl0p: working decryptors
  • Symmetric keys captured at first use
  • Working decryptors for Akira, BlackCat, LockBit, Cl0p
  • Decrypt in place. No ransom, no backup restore needed.
No Ransom · Decrypt in Place
The Gap

What EDRs Need vs. What Morphisec Needs

Every technique in this engagement was designed to defeat the detection stack. Here's why it works, and why Morphisec doesn't care.

EDR Detection Stack
Requires prior knowledge of the threat
  • Known file hash or signature: payload is polymorphic, unique every build
  • Behavioral pattern match: I/O stays below detection thresholds
  • Threat intel feed correlation: binary has never been submitted anywhere
  • Suspicious parent process chain: delivery uses trusted tools (cmd, RMM)
  • Kernel callbacks intact: BYOVD strips them before payload runs
  • Network reputation scoring: HTTPS to known CDN endpoints
Result: 0 / 3 scenarios detected
Morphisec AMTD
Requires no prior knowledge of the threat
  • Memory layout randomized at runtime. Exploit has no valid target address.
  • Execution intercepted at the memory layer, before any file I/O.
  • ETW + AMSI tampering detected and blocked in memory
  • Exfil tool execution blocked regardless of delivery method or reputation
  • Symmetric encryption keys captured at first use. Enables decryption.
  • Deterministic prevention events flow to SIEM as high-fidelity alerts
Result: 3 / 3 scenarios blocked
After Registration

What You'll Receive

Your session includes pre- and post-engagement materials not available publicly.

Within 24h
Session Confirmation
Calendar invite with time slot, location, and prep instructions.
Pre-Session
Attack Scenario Briefs
Detailed kill chain breakdowns, MITRE ATT&CK mappings, and technique analysis for all three scenarios.
Pre-Session
Threat Landscape Report
Current TTP trends, ransomware actor profiles, and the AI-accelerated exploit timeline for your industry.
Post-Session
Results & Key Captures
Detection rates, interception evidence, captured encryption keys, and remediation artifacts.
Black Hat USA 2026

Apply for a Session

By invitation only. NDA required before confirmation. Limited sessions for direct access to Morphisec's engineering team.

NDA required before confirmation
Limited to 8 sessions per day
CISO / VP / Director level preferred
Bring your own EDR. We'll test against it.

Application Received

The Morphisec team will confirm your session within 24 hours.
Check your inbox for your calendar invite, scenario briefs, and pre-session materials.