mirror of
https://github.com/andreisss/Remote-DLL-Injection-with-Timer-based-Shellcode-Execution
synced 2026-06-06 15:14:31 +00:00
c751ded2797d8e427f0e7f7bcfb7edd00ef1c3fa
Thread Pool Timer Process Injection
⚠ Educational Research Only
This repository contains security research for educational purposes and authorized use only.
Use responsibly and in accordance with all applicable laws and regulations.
Overview
Thread Pool Timer Process Injection is a technique that leverages the Windows thread pool to execute shellcode. Using the classic DLL injection with CreateThreadpoolTimer to run shellcode in-memory using legit system threads, stealthy, and likely to slip past modern defenses
This approach introduces a stealthy execution vector that avoids classic API hooks such as CreateRemoteThread, NtCreateThreadEx, and APCs, making it highly attractive for red team operations and malware research.
🛠️ Technical Implementation
🧩 Core Components
🛠 Main Injector (Injector.cpp)
- Process enumeration and targeting logic
- DLL injection using
CreateRemoteThreadandLoadLibraryW - Error handling and execution status reporting
⏲ Timer DLL (TimerDLL.cpp)
- Timer-based shellcode execution implementation
TP_CALLBACK_ENVIRONstructure setup for thread pool configuration- Execution of shellcode via the timer callback
📋 API Sequence
🧪 Traditional Injection APIs
OpenProcess() // Access the target process
VirtualAllocEx() // Allocate memory in remote process
WriteProcessMemory() // Write shellcode or DLL path
CreateRemoteThread() // Create a remote thread to execute payload
LoadLibraryW() // Load a DLL via thread execution
⏱️ Thread Pool Timer-Based APIs
InitializeThreadpoolEnvironment() // Configure threadpool callback environment
CreateThreadpoolTimer() // Create a timer object
SetThreadpoolTimer() // Schedule the timer for execution
TimerCallback() // Callback function that executes shellcode
Languages
C++
100%