DarkWidow
★ 0
updated 2y ago
⑂ fork
Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing + Api resolving from TIB + API hashing
No plain-English explanation yet — one is being written right now. Check back in a minute.