Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.
Using Thread Description To Hide Shellcode
翻译 - 使用线程描述隐藏Shellcode