Hack.lu 2026

Cloak and Filter: Weaponizing the GPU and Windows Cloud Filter for File-less Execution and Privilege Escalation

Security solutions have long since established absolute control over disk I/O and user-land memory. Every step you take, you generate telemetry. To survive, attackers need to operate where EDRs and other solutions cannot see. However, most attack surfaces include touching the disk or RAM, triggering monitored disk writes or creating suspicious memory allocations.

This talk introduces a novel attack surface that bypasses this barrier by weaponizing the Windows Cloud Filter and its API (CFAPI). Although CFAPI was originally designed for cloud storage providers, we abuse it to bridge the gap from untouchable memory space of the GPU directly to the attacking Cloud Provider.

We will demonstrate how our 0-byte file placeholders can achieve PE while not triggering a single event on a fully patched Windows 11 machine. Compute Shaders will decrypt the payload entirely on the GPU, completely bypassing traditional monitoring.

Attendees will learn how to conduct low-level attack surface research, observing all the steps we went through. The obstacles of our research journey will be noted so the audience will learn from our mistakes. The undocumented structures and flows of the attack surface will be shown and dissected. Attendees will walk away from this talk with enough knowledge and ideas to continue where this research left off.


Presentation Outline

1. INTRODUCTION (5 Minutes)

  • The Gap: We will start by talking about the current state of EDR evasion. User-land hooking bypasses and traditional Process Injections are getting caught. Threat actors are looking for new places to hide their code, and soon they will start hiding behind the GPU.

  • The Trap: We will go through the notorious obstacle with the GPU: It can’t execute a Windows PE file on its own. Having the payload reside in the system memory (RAM) creates a massive footprint for EDRs to detect. We will pitch the core pillar of this talk: What if we could stream the payload to the Kernel directly from the GPU pipeline, skipping the standard user-mode memory allocations entirely?

2. THE ARCHITECTURE: BUILDING A BRIDGE (5 Minutes)

  • Cloud Filter (cldflt.sys): We’ll start with an explanation of cldflt.sys and its internal structure.
    Its goal is to serve Cloud providers like OneDrive and Dropbox, featuring “placeholder” creation on the disk for cloud on-demand streaming. We will also explain how we set up our API and use its callbacks to fetch data from the GPU, in preparation for our attacks.

  • Compute Shaders: We will cover Compute Shaders and how we can move an encrypted payload into the GPU’s VRAM, using a simple XOR Compute Shader to decrypt it on the go for CFAPI's callback for streaming the data.

3. THEORITICALY PERFECT: OVERCOMING EVASION OBSTACLES (5 Minutes)

  • In this section we will break down the theoretical "perfect" evasion and contrast it with the obstacles we encountered, explaining how we overcame them.

  • 1. The Filtering Obstacle: We will explain how we started by building a mechanism that serves the payload to the System process but feeds zeroes to an EDR. Then, we will detail why this user-mode filtering approach ultimately fails against modern EDRs, as you cannot reliably block highly privileged services or kernel callbacks without breaking the OS loader's access to the file.

  • 2. The Unwinnable Race: We will go over the "Burn After Reading" concept and why relying on CFAPI's NotifyFileClose Callback to dehydrate the file is too little and too late to evade modern security solutions.

  • 3. The Trigger: We will conclude this section by explaining that the novelty of this attack surface isn't in “killing” security solutions, but in denying the EDR of the trigger. Because the CFAPI placeholder and payload hydration never cause a kernel-mode I/O callback, the EDR's rules and heuristics are never alerted to scan the file in the first place, allowing us to escalate privileges uninterrupted.

4. WEAPONIZATION: ZERO-WRITE ESCALATION (10 Minutes)

  • This section goes over our attack flows and features 3 attacks on a fully patched Windows 11 machine. Each attack covers a different traditional attack vector that is complemented by chaining our new attack surface.

  • Shellcode: We will demonstrate how our Cloud Provider writes encrypted shellcode to the GPU, uses the GPU to decrypt it, maps it and finally runs it without detection.

  • Process Creation: We will demonstrate how our Cloud Provider writes an encrypted payload to the GPU’s VRAM, decrypts it using the GPU, fetches the payload and creates a process from it. The payload will be a notorious malicious sample, with no detections.

  • DLL: Ultimately, we will demonstrate how to chain this technique for LPE. By placing a virtual CFAPI placeholder in a trusted directory, we can hijack trusted processes to achieve privilege escalation, eventually escalating to NT AUTHORITY\SYSTEM, without detection.

5. CONCLUSIONS AND TAKEAWAYS (5 Minutes)

  • Takeaways:
    • First, we will summarize the attacks, emphasizing how a new attack surface can complement existing vectors by chaining them one after the other.
    • Then, we will point out what the audience can learn from our mistakes and how researchers can continue from where we stopped.
  • Mitigations: We will provide actionable steps for defenders:
    • How to monitor Cloud Filter sync roots registration.
    • How to monitor non-graphical Compute Shaders initialization and use.
  • Conclusions: We suggest that the cybersecurity community’s focus should shift. As we transition into a GPU-centric infrastructure driven by AI training and inference, the GPU is no longer peripheral. “Cloak and Filter” is just the first step, researchers can use our research to identify similar gaps and attack surfaces.
David Shandalov

David Shandalov is a Staff Security Researcher at Palo Alto Networks, where he focuses on post-exploitation techniques, tracking the evolving malware threat landscape and Identity Security.

Previously, David worked as a Mobile Malware Researcher at Check Point and as a Security Researcher at Deep Instinct, gaining hands-on experience across multiple security doctrines and attack surfaces and presenting his findings at DEF CON. Outside of cybersecurity, he enjoys flying as a licensed private pilot.