Driver listens input and output pipes in two special threads. Purpose of each of them writing data into pipes and reading it. Scheme of working stdin dispatcher thread:
Another interesting feature of rootkit – method with help of which it do pages of process writable.
posted by https://twitter.com/artem_i_baranov