Code Injection, Process Hollowing, and API Hooking
Abhijit Mohanta, Anoop Saldanha · Apress eBooks · 2020
Malware can drop new files on the system, create new registry keys and values, initiate network connections, create new processes, insert new kernel modules, and so forth. Malware can also force/inject/insert itself into and modify existing running processes, including OS processes and the underlying kernel. But most of these techniques used by the malware for this are not the ones discovered or invented by malware attackers but are techniques used by many of the legitimate software, especially antimalware products.