这里有些技术没听说过,记录一下:
Fileless execution with remote staged encrypted binary or shellcode.
Early Bird APC injection.
Process masquerading.
Supports Named Pipes.
Strings and function calls obfuscation.
Mortar covert reload subroutine.
Delay execution techniques. - 暂不清楚怎么delay的