Wslink: Unique and undocumented malicious loader that runs as a server
ESET research discovers a unique loader for Windows binaries that, unlike other such loaders, runs as a server and executes received modules in memory.
United States Trojandownloader Wslink Wslinkclient Github System Services Software Packing Service Execution
Source: welivesecurity.com