Actor(s): APT29, Lazarus Group

sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.

2022-06-17Github (monoxgas)Nick Landers
sRDI - Shellcode Reflective DLL Injection

There is no Yara-Signature yet.