Ctrl+Inject Process Manipulating

This technique uses a callback function for Control signal handlers to inject the malicious code. Each time a control signal, such as Ctrl+C, is received by a process the system creates a new thread to execute the function. The thread is created by legitimate process “csrss.exe” in the system, rendering the detection more difficult.

