Windows parent process ID spoofing allows attackers to create a new process that appears to have been launched by a trusted parent such as explorer.exe, undermining detections based on parent-child process relationships. MITRE ATT&CK tracks the method as T1134.004, noting it can be used for both defense evasion and, in some cases, privilege escalation by assigning a privileged parent so the child may inherit an elevated token.
A published C++ proof of concept demonstrated the technique by using CreateProcess with extended startup attributes to set PROC_THREAD_ATTRIBUTE_PARENT_PROCESS, launching mspaint.exe in a suspended state, injecting a payload, queueing execution with APC, and then resuming the thread so the process appeared to be a child of explorer.exe. The walkthrough said the sample was detected by 20 of 70 VirusTotal engines and linked the tradecraft to real-world offensive tooling and malware, including Cobalt Strike and KONNI RAT, highlighting how adversaries can disguise execution chains that would otherwise look suspicious.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A technical walkthrough demonstrated creating mspaint.exe with explorer.exe as a spoofed parent using CreateProcess extended attributes, then injecting code via APC into the suspended process. The author also reported that the compiled sample was detected by 20 of 70 VirusTotal engines.
MITRE ATT&CK published the Enterprise sub-technique T1134.004 covering Parent PID Spoofing as a Windows defense-evasion and privilege-escalation method.
The cocomelonc reference states that Didier Stevens introduced parent PID spoofing to a wider information security audience in 2009.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.