Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Stack rumbling” was a process-launch denial-of-service technique reported in Earth Longzhi activity in 2023. The group’s SPHijacker tool changed a Windows Image File Execution Options (IFEO) registry value called MinimumStackCommitInBytes; Trend Micro said an excessively large value caused selected security applications to crash when launched. SPHijacker also had a separate method: using a vulnerable Zemana driver to terminate security processes that were already running.

How stack rumbling works

Windows IFEO settings can be associated with particular executable names. In the reported technique, SPHijacker altered an IFEO setting for selected security applications and set MinimumStackCommitInBytes to an excessively large value. Trend Micro described the value as undocumented and reported that affected programs crashed as they started. The practical effect was to make those applications unavailable through repeated launch failure—not to physically damage the computer.

The term “stack rumbling” was coined by Trend Micro researchers for this IFEO-based denial of service. In contemporaneous reporting, researchers Ted Lee and Hara Hiroaki described it as a “new denial-of-service (DoS) technique.” That is their characterization of the finding, not independent proof that no similar technique had ever existed. Infosecurity Magazine reported the statement on May 3, 2023.

How it differs from SPHijacker’s driver method

The campaign analysis describes two distinct ways SPHijacker could interfere with security products. One disrupts application launches through IFEO; the other uses a vulnerable driver to terminate processes. The sources do not compare their success rates or establish that one was more effective.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Method What it does Dependency Defensive review focus
Stack rumbling Changes an IFEO registry value so a targeted application crashes at launch. Unexpected IFEO configuration, including MinimumStackCommitInBytes. Unexplained IFEO changes and repeated launch crashes affecting security applications.
Vulnerable-driver termination Uses a driver to terminate security-product processes. zamguard64.sys, a vulnerable Zemana driver associated in the campaign report with CVE-2018-5713. Unexpected driver loading, driver-related service creation, and security processes terminating unexpectedly.

The CERT-EU Cyber Security Brief 23-06 also describes the driver-related approach. These are complementary avenues in the report, not two names for the same technique.

Where stack rumbling appeared in the campaign

Trend Micro attributed the activity to Earth Longzhi, which it identifies as an APT41 subgroup. Its 2023 reporting described attacks against organizations in Taiwan, Thailand, the Philippines, and Fiji in government, healthcare, manufacturing, and technology. Decoy documents in analyzed samples suggested possible interest in Vietnam and Indonesia; they do not establish that organizations there were victims.

The reported intrusion chain began with exploitation of vulnerable public-facing applications, including IIS and Microsoft Exchange servers. The attackers deployed the Behinder web shell, then abused legitimate Windows Defender executables to sideload DLLs. Trend Micro described two payloads in this activity: Croxloader, a customized Cobalt Strike loader, and SPHijacker, the tool used to disable security products. The campaign details are summarized by Philippine NCERT on May 4, 2023.

What defenders can review

The campaign reporting does not provide a complete validated detection rule or evidence that a particular security product reliably stops stack rumbling. It does point to concrete areas for investigation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Check whether public-facing IIS, Exchange, and other application servers were patched at the time of suspected exposure, and investigate signs of exploitation or unexpected Behinder web-shell deployment.
  • Review alerts and telemetry for DLL sideloading through legitimate Windows Defender executables, especially when the loaded DLL or execution context is unexpected.
  • Investigate unexplained changes to IFEO settings for security applications, including abnormal MinimumStackCommitInBytes values, and correlate them with application launch crashes.
  • Review unexpected driver loads and service creation associated with zamguard64.sys, as well as unexplained termination of security processes.

Philippine NCERT’s advisory emphasizes keeping software patched, particularly public-facing applications. These checks are investigative priorities drawn from the reported behavior, not a guarantee that any single control will prevent it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reporting establishes—and what it does not

The technique and campaign were reported in 2023. The available campaign sources do not establish whether Earth Longzhi is still using stack rumbling, how many victims were affected, how many products were disabled, or how often the technique succeeded. Trend Micro’s broader midyear report gives company-wide telemetry for the first half of 2023, but those figures are not Earth Longzhi case counts and should not be read as campaign impact estimates. Trend Micro’s 2023 Midyear Cybersecurity Threat Report reports 85,629,564,910 overall threats blocked, including 37.0 billion blocked email threats, 1.1 billion malicious URLs, and 45.9 billion malicious files; it also records reputation-query totals. Those numbers describe Trend Micro telemetry, not infections or victims in this campaign.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.