APC Injection into dllhost.exe via NtQueueApcThread with Unbacked Memory and Network Egress (ACRStealer)
Detects APC injection into dllhost.exe unbacked/private memory via NtQueueApcThread correlated with a subsequent outbound network connection from the same process — the ACRStealer injection-and-C2 pattern.
Cortex XDR

