"inject" - writes shellcode into process, which can be specified by PID. "spawn" - launches new suspended process, writes shellcode and creates thread. PPID can be specified. Shellcode is encrypted on server, decrypted right before writing to memory and cleared right after it. Tiny-AES is used for decryption. Modules are now dynamically loaded from folder and not harcoded.