DLL Injeciton
It is a process of forcing a remote process to load malicious DLL. Okay..but what is a DLL?😐 DLL - Dynamic-Link Library - It is Microsoft's way to use libraries to share code among multiple applications. These libraries contain code and data that can be used by multiple programs at the same time. Examples kernel32.dll - access and manipulation of files and folders. gdi32.dll - used for displaying and manipulating graphics. ntdll.dll - interface to windows kernel. wsock32.dll - used by Internet and network applications to handle network connections. In-Depth : In this technique, malware writes the path of malicious DLL inside a remote process using Windows API functions then invokes the execution of that DLL by creating a remote thread in the target application. As shown in the above picture, we have a launcher file that will be responsible for performing injection of mal.dll (dll containing malicious code) into the target.exe (victim - any wind...