ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1574.001×

75 examples

TechniqueUsed byProcedure example
T1574.001
DLL
MalwareRamsay

Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload.

T1574.001
DLL
MalwareAshTag

AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32.

T1574.001
DLL
MalwareSysUpdate

SysUpdate can load DLLs through vulnerable legitimate executables.

T1574.001
DLL
MalwarePowGoop

PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`.

T1574.001
DLL
MalwareANELLDR

ANELLDR can use DLL sideloading from a legitimate application to initiate execution.

T1574.001
DLL
MalwareLookBack

LookBack side loads its communications module as a DLL into the libcurl.dll loader.

T1574.001
DLL
MalwareEgregor

Egregor has used DLL side-loading to execute its payload.

T1574.001
DLL
MalwareMelcoz

Melcoz can use DLL hijacking to bypass security controls.

T1574.001
DLL
MalwareHIUPAN

HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe.

T1574.001
DLL
MalwaremetaMain

metaMain can support an HKCMD sideloading start method.

T1574.001
DLL
MalwareHTTPBrowser

HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading.

T1574.001
DLL
MalwareMirageFox

MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary.

T1574.001
DLL
MalwarePcexter

Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.

T1574.001
DLL
MalwareStarProxy

StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe.

T1574.001
DLL
MalwareBADNEWS

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.

T1574.001
DLL
MalwareGoopy

Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google.

T1574.001
DLL
MalwareAstaroth

Astaroth can launch itself via DLL Search Order Hijacking.

T1574.001
DLL
MalwareQakBot

QakBot has the ability to use DLL side-loading for execution.

T1574.001
DLL
MalwareDridex

Dridex can abuse legitimate Windows executables to side-load malicious DLL files.

T1574.001
DLL
MalwareDenis

Denis exploits a security vulnerability to load a fake DLL and execute its code.

T1574.001
DLL
MalwareWaterbear

Waterbear has used DLL side loading to import and load a malicious DLL loader.

T1574.001
DLL
MalwareUPPERCUT

UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation.

T1574.001
DLL
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.

T1574.001
DLL
ToolEmpire

Empire contains modules that can discover and exploit various DLL hijacking opportunities.

T1574.001
DLL
ToolBrute Ratel C4

Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.