Primitive Process Injection: APC Tandem cover illustration

APC Tandem: A Primitive-Chaining Process Injection That Slips Past Common EDR Triggers

A walkthrough of “APC Tandem”, a stealth Windows process-injection technique that replaces WriteProcessMemory, CreateRemoteThread and VirtualAllocEx with a chain of less-watched primitives — thread description smuggling, paired GetThreadDescription/RtlMoveMemory APCs, and a Special User APC for execution.