Am I reading this correctly:
* 1st: Adjust the overprovisioning area and hope that the filesystem does not budge,
* 2nd: run the malware as it is now accessible and
* 3rd: change the overprovisioning again to hide the malware again?
Or is the malware executing from non-partitioned disk space?