INTEL_REPORT
Google Project Zero · published 12/16/2025, 9:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Thinking Outside The Box [dusted off draft from 2017] Preface Hello from the future! This is a blogpost I originally drafted in early 2017. I wrote what I intended to be the first half of this post (about escaping from the VM to the VirtualBox host userspace process with CVE-2017-3558), but I never got around to writing the second half (going from the VirtualBox host userspace process to the host kernel), and eventually sorta forgot about this old post draft… But it seems a …
https://projectzero.google/2025/12/thinking-outside-the-box.html
sha256:9575c65b56dee7c69497e998bd9bf2a8e73d2560a9d11ad8fab4c1378883f62b
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.