T1220 - Tagged - Security Boulevard
Dridex’s Bag of Tricks: An Analysis of its Masquerading and Code Injection Techniques

Dridex’s Bag of Tricks: An Analysis of its Masquerading and Code Injection Techniques

A new variant of Dridex observed in July 2019 masquerades as legitimate Windows system processes to avoid detection. The variant uses five code injection techniques during its infection lifecycle: AtomBombing, DLL order ...