Ransomware Series: DeepLoad APC Injection into Suspended LockAppHost/makecab/Mag

Detects the DeepLoad malware staging process injection by spawning trusted Windows binaries (LockAppHost.exe, makecab.exe, or Magnify.exe) in a suspended state from an unauthorized parent process. This behavior is indicative of an APC-based injection sequence where malicious code is written into the suspended process before execution.