Process Injection and Migration Techniques: * Strategies to Bypass Security Software of Network Communication after a Successful Reverse shell
Jean Rosemond Dora, Ladislav Hluchý · 2025
From our previous paper, entitled “Dangerousness of Client-Side Code Execution with Microsoft Office” [1], we have demonstrated various ways to obtain a reverse shell after performing a successful phishing attack. Even though a phishing attack can bypass the antivirus software upon arrival on a victim's computer, there might be some security software that is in place to detect the network communication from a process, and hence block our shell. The reason behind this scene is that any received Meterpreter shell or a similar shell must be executed within a process. Therefore, to avoid these barriers, an attacker may use the process injection and/or the migration techniques to inject codes into other inner applications. Additionally, to migrate to distinct processes. Another important benefit of this approach can fight against the following: after gaining a reverse shell, and starting the enumeration inside the victim's environment, if the victim closes the application, then it will cause the shutdown of our shell. This will affect the attacker as he will need to relaunch the attack from scratch. This paper will focus on the examination of the inner workings of the aforementioned techniques. It will help us continue with our post-exploitation scenario. Further, we will briefly elaborate on the implementation of the “process injection” using C-sharp programming language. We will also succinctly discuss the followings: DLL injection and process hollowing which consists of altering a process before it starts that may require a high privilege.