In this section we will take about the how to perform code injection using Asynchronous procedure call

Untitled

Now, Let’s Get Deeper to the APC Code Injection.

Untitled

Now, Let’s Get More Deeper.

Assume we have those two process.

Untitled

  1. We have Malware Process.
  2. Legitimate Process.

We will put the Legitimate Process in Sleep State.

Then We Will Queue Our APC Function.

Untitled

Notice that the APC Function is now Queued.