Andrea Bocchetti 9265c00ffc Update README.md
2025-07-17 20:00:04 +02:00
2025-07-16 17:43:43 +02:00
2025-07-16 17:43:43 +02:00
2025-07-16 17:43:43 +02:00
2025-07-16 17:43:43 +02:00
2025-07-16 17:25:26 +02:00
2025-07-17 20:00:04 +02:00

Thread Pool Timer Process Injection

Educational Research Only
This repository contains security research for educational purposes and authorized use only.
Use responsibly and in accordance with all applicable laws and regulations.


Overview

Thread Pool Timer Process Injection is a technique that leverages the Windows thread pool infrastructure to execute shellcode. By combining traditional DLL injection with the CreateThreadpoolTimer API, this method enables in-memory code execution through legitimate system-managed threads—potentially bypassing many modern detection mechanisms.

This approach introduces a stealthy execution vector that avoids classic API hooks such as CreateRemoteThread, NtCreateThreadEx, and APCs, making it highly attractive for red team operations and malware research.


Recording 2025-07-16 1317152323



🛠️ Technical Implementation

image

🧩 Core Components

🛠 Main Injector (Injector.cpp)

  • Process enumeration and targeting logic
  • DLL injection using CreateRemoteThread and LoadLibraryW
  • Error handling and execution status reporting

⏲ Timer DLL (TimerDLL.cpp)

  • Timer-based shellcode execution implementation
  • TP_CALLBACK_ENVIRON structure setup for thread pool configuration
  • Execution of shellcode via the timer callback

📋 API Sequence

🧪 Traditional Injection APIs

OpenProcess()           // Access the target process
VirtualAllocEx()        // Allocate memory in remote process  
WriteProcessMemory()    // Write shellcode or DLL path
CreateRemoteThread()    // Create a remote thread to execute payload
LoadLibraryW()          // Load a DLL via thread execution


⏱️ Thread Pool Timer-Based APIs

InitializeThreadpoolEnvironment()  // Configure threadpool callback environment
CreateThreadpoolTimer()            // Create a timer object
SetThreadpoolTimer()               // Schedule the timer for execution
TimerCallback()                    // Callback function that executes shellcode
S
Description
Automated archival mirror of github.com/andreisss/Remote-DLL-Injection-with-Timer-based-Shellcode-Execution
Readme GPL-3.0 87 KiB
Languages
C++ 100%