Real-world descriptions of how a group, tool or campaign used a technique.
75 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.001 DLL |
MalwareNinja | Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player. |
| T1574.001 DLL |
MalwareRCSession | RCSession can be installed via DLL side-loading. |
| T1574.001 DLL |
MalwareIronWind | IronWind has used DLL sideloading for execution. |
| T1574.001 DLL |
MalwareDowndelph | Downdelph uses search order hijacking of the Windows executable sysprep.exe to escalate privileges. |
| T1574.001 DLL |
MalwareChinoxy | Chinoxy can use a digitally signed binary ("Logitech Bluetooth Wizard Host Process") to load its dll into memory. |
| T1574.001 DLL |
MalwarePAKLOG | PAKLOG has leveraged legitimate binaries to conduct DLL side-loading. |
| T1574.001 DLL |
MalwareRedLeaves | RedLeaves is launched through use of DLL search order hijacking to load a malicious dll. |
| T1574.001 DLL |
MalwareHavoc | Havoc has leveraged legitimate executables to side-load malicious payloads. |
| T1574.001 DLL |
MalwareWEBC2 | Variants of WEBC2 achieve persistence by using DLL search order hijacking, usually by copying the DLL file to |
| T1574.001 DLL |
MalwareNebulae | Nebulae can use DLL side-loading to gain execution. |
| T1574.001 DLL |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution. |
| T1574.001 DLL |
MalwareTONESHELL | TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadATTACKIQ MUSTANG PANDA TONESHELL March 2023CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Trend Micro Mustang Panda Earth Preta TONESHELL June 2023Trend Micro Mustang Panda Earth Preta Toneshell February 2025Zscaler |
| T1574.001 DLL |
MalwareRainyDay | RainyDay can use side-loading to run malicious executables. |
| T1574.001 DLL |
MalwareEcipekac | Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL. |
| T1574.001 DLL |
MalwareBOOKWORM | BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`. |
| T1574.001 DLL |
MalwarePrikormka | Prikormka uses DLL search order hijacking for persistence by saving itself as ntshrui.dll to the Windows directory so it will load before the legitimate ntshrui.dll saved in the System32 subdirectory. |
| T1574.001 DLL |
MalwarePUBLOAD | PUBLOAD has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42PaloAlto MUSTANG PANDA PUBLOAD MARCH 2024 |
| T1574.001 DLL |
MalwareCANONSTAGER | CANONSTAGER has abused legitimate executables to side-load malicious DLLs. |
| T1574.001 DLL |
MalwareLoFiSe | LoFiSe has been executed as a file named DsNcDiag.dll through side-loading. |
| T1574.001 DLL |
MalwareWastedLocker | WastedLocker has performed DLL hijacking before execution. |
| T1574.001 DLL |
MalwareInvisiMole | InvisiMole can be launched by using DLL search order hijacking in which the wrapper DLL is placed in the same folder as explorer.exe and loaded during startup into the Windows Explorer process instead of the legitimate library. |
| T1574.001 DLL |
MalwareCLAIMLOADER | CLAIMLOADER has used a legitimately signed executable to execute a malicious payload within a DLL file. |
| T1574.001 DLL |
MalwareZeroT | ZeroT has used DLL side-loading to load malicious payloads. |
| T1574.001 DLL |
MalwareRaspberry Robin | Raspberry Robin can use legitimate, signed EXE files paired with malicious DLL files to load and run malicious payloads while bypassing defenses. |
| T1574.001 DLL |
MalwareHUI Loader | HUI Loader can be deployed to targeted systems via legitimate programs that are vulnerable to DLL search order hijacking. |
| T1574.001 DLL |
MalwareBOOSTWRITE | BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll. |
| T1574.001 DLL |
MalwareHyperBro | HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload. |
| T1574.001 DLL |
MalwareSplatDropper | SplatDropper has leveraged legitimate binaries to conduct DLL side-loading. |
| T1574.001 DLL |
MalwareJavali | Javali can use DLL side-loading to load malicious DLLs into legitimate executables. |
| T1574.001 DLL |
MalwareBBSRAT | DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper. |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1574.001 DLL |
MalwareNOOPLDR | NOOPLDR can be executed via sideloading. |
| T1574.001 DLL |
MalwareLumma Stealer | Lumma Stealer has leveraged legitimate applications to then side-load malicious DLLs during execution. |
| T1574.001 DLL |
MalwareClambling | Clambling can store a file named `mpsvc.dll`, which opens a malicious `mpsvc.mui` file, in the same folder as the legitimate Microsoft executable `MsMpEng.exe` to gain execution. |
| T1574.001 DLL |
MalwareDarkGate | DarkGate includes one infection vector that leverages a malicious "KeyScramblerE.DLL" library that will load during the execution of the legitimate KeyScrambler application. |
| T1574.001 DLL |
MalwareFoggyWeb | FoggyWeb's loader has used DLL Search Order Hijacking to load malicious code instead of the legitimate `version.dll` during the `Microsoft.IdentityServer.ServiceHost.exe` execution process. |
| T1574.001 DLL |
MalwareChaes | Chaes has used search order hijacking to load a malicious DLL. |
| T1574.001 DLL |
MalwareLODEINFO | LODEINFO can use legitimate EXE files to sideload malicious DLLs. |
| T1574.001 DLL |
MalwareMetamorfo | Metamorfo has side-loaded its malicious DLL file. |
| T1574.001 DLL |
MalwareT9000 | During the T9000 installation process, it drops a copy of the legitimate Microsoft binary igfxtray.exe. The executable contains a side-loading weakness which is used to load a portion of the malware. |
| T1574.001 DLL |
Malwaregh0st RAT | A gh0st RAT variant has used DLL side-loading. |
| T1574.001 DLL |
MalwareKerrdown | Kerrdown can use DLL side-loading to load malicious DLLs. |
| T1574.001 DLL |
MalwareCrutch | Crutch can persist via DLL search order hijacking on Google Chrome, Mozilla Firefox, or Microsoft OneDrive. |
| T1574.001 DLL |
MalwareHikit | Hikit has used DLL to load |
| T1574.001 DLL |
MalwareStrelaStealer | StrelaStealer has sideloaded a DLL payload using a renamed, legitimate `msinfo32.exe` executable. |
| T1574.001 DLL |
MalwareSakula | Sakula uses DLL side-loading, typically using a digitally signed sample of Kaspersky Anti-Virus (AV) 6.0 for Windows Workstations or McAfee's Outlook Scan About Box to load malicious DLL files. |
| T1574.001 DLL |
MalwareCorKLOG | CorKLOG has leveraged legitimate binaries to conduct DLL side-loading. |
| T1574.001 DLL |
MalwarePandora | Pandora can use DLL side-loading to execute malicious payloads. |
| T1574.001 DLL |
MalwareFinFisher | FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking. |
| T1574.001 DLL |
MalwareWingbird | Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.