Code Injection, Process Hollowing, and API Hooking

Abhijit Mohanta, Anoop Saldanha · Apress eBooks · 2020

Malware can drop new files on the system, create new registry keys and values, initiate network connections, create new processes, insert new kernel modules, and so forth. Malware can also force/inject/insert itself into and modify existing running processes, including OS processes and the underlying kernel. But most of these techniques used by the malware for this are not the ones discovered or invented by malware attackers but are techniques used by many of the legitimate software, especially antimalware products.

Read the paper · More papers on PaperTik