A forum for reverse engineering, OS internals and malware analysis 

 #29078  by DMEW
 Sun Aug 21, 2016 6:16 pm
Is there any special reason why malware sometimes opts for process hollowing vs injection? They seem to achieve the same result, yet dll injection with createRemoteThread is much easier to implement and maintains the original process' code which may help hide it more. Whats the benefit?
 #29102  by EP_X0FF
 Thu Aug 25, 2016 3:13 pm
Oh you mean zombie process. The only benefit is AV/FW bypass. This applies to the use of any non-CreateRemoteThread methods.