Cyberbit researchers show how APC in conjunction with a suspended process avoids AV detection

Early Bird code injection method relies on a Windows built-in APC (Asynchronous Procedure Calls) function that allows applications to execute code asynchronously in the context of a particular thread.