logo

Malware Series: Process Injection Mapped Sections

ID: b6867162-7feb-58fd-ad3c-d8af751f4991

STIX ID: report--b6867162-7feb-58fd-ad3c-d8af751f4991

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-27

Date Updated: 2026-05-01

...
...

This report is a technical how-to describing a Windows process-injection technique using NtCreateSection/NtMapViewOfSection to create a kernel-backed shared memory section, map views into local and remote processes, copy shellcode (msfvenom example) into the shared view, and execute it via a remote thread; C and C# code examples are provided to demonstrate the method.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.