
Memory API proxy via signed mozglue.dll
Detection research PoC: proxy memory operations (memory mapping, local memory allocation) through Mozilla's signed mozglue.dll so kernel callbacks attribute the final user module to a trusted vendor DLL (Mozilla signed) instead of untrusted or unsigned module.
Both are MFBT_API exports from mozglue.dll (Firefox install required):
| Mode | Export | Mozilla source |
|---|---|---|
inject | mozilla::MapRemoteViewOfFile | WindowsMapRemoteView.cpp · header |
alloc | MozVirtualAlloc | mozjemalloc.cpp · mozmemory_wrap.h |
x64 MSVC mangled names:
?MapRemoteViewOfFile@mozilla@@YAPEAXPEAX0_K01KK@Z
MozVirtualAlloc
MSYS2 mingw-w64:
./build.sh
./build.sh shellcode # optional: rebuild shellcode/msgbox.bin
A prebuilt mozglue_gate.exe is included in the repo for quick detection-engineering tests (64-bit, requires Firefox installed).
# Cross-process map + APC (MapRemoteViewOfFile)
.\mozglue_gate.exe inject <pid> shellcode\msgbox.bin
# Local RWX alloc (MozVirtualAlloc)
.\mozglue_gate.exe alloc --size 10240
shellcode/msgbox.bin pops "Hello from Mozglue" / caption gluegate (no child process).
Requires classic Firefox: C:\Program Files\Mozilla Firefox\mozglue.dll (or --mozglue / MOZGLUE_DLL).
Final user module is Mozilla Corporation signed/trusted
MapViewOfFile
VirtualAlloc
mozglue.dll!MozVirtualAlloc or mozglue.dll!?MapRemoteViewOfFile in call stack from unsigned or non Mozilla signed process.mozilla.dll (especially already installed one in programfiles).For authorized security research and detection testing only.