For this week's TTP Tuesday we are releasing a new APT40 themed chain that showcases shellcode injection and defense evasion through use of OS native API. The release includes a dozen or new executors, available currently in Sliver agents, so you can avoid dropping into a shell.
This chain starts by injecting shellcode into a target process to launch calc.exe. It then demonstrates a number of new executors, such as registryread, mkdir, and getprivs, that you can mix into your own chains for better stealth.