Real-world descriptions of how a group, tool or campaign used a technique.
75 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.001 DLL |
MalwareRamsay | Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload. |
| T1574.001 DLL |
MalwareAshTag | AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32. |
| T1574.001 DLL |
MalwareSysUpdate | SysUpdate can load DLLs through vulnerable legitimate executables. |
| T1574.001 DLL |
MalwarePowGoop | PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`. |
| T1574.001 DLL |
MalwareANELLDR | ANELLDR can use DLL sideloading from a legitimate application to initiate execution. |
| T1574.001 DLL |
MalwareLookBack | LookBack side loads its communications module as a DLL into the |
| T1574.001 DLL |
MalwareEgregor | Egregor has used DLL side-loading to execute its payload. |
| T1574.001 DLL |
MalwareMelcoz | Melcoz can use DLL hijacking to bypass security controls. |
| T1574.001 DLL |
MalwareHIUPAN | HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe. |
| T1574.001 DLL |
MalwaremetaMain | metaMain can support an HKCMD sideloading start method. |
| T1574.001 DLL |
MalwareHTTPBrowser | HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading. |
| T1574.001 DLL |
MalwareMirageFox | MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary. |
| T1574.001 DLL |
MalwarePcexter | Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading. |
| T1574.001 DLL |
MalwareStarProxy | StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe. |
| T1574.001 DLL |
MalwareBADNEWS | BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable. |
| T1574.001 DLL |
MalwareGoopy | Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google. |
| T1574.001 DLL |
MalwareAstaroth | Astaroth can launch itself via DLL Search Order Hijacking. |
| T1574.001 DLL |
MalwareQakBot | QakBot has the ability to use DLL side-loading for execution. |
| T1574.001 DLL |
MalwareDridex | Dridex can abuse legitimate Windows executables to side-load malicious DLL files. |
| T1574.001 DLL |
MalwareDenis | Denis exploits a security vulnerability to load a fake DLL and execute its code. |
| T1574.001 DLL |
MalwareWaterbear | Waterbear has used DLL side loading to import and load a malicious DLL loader. |
| T1574.001 DLL |
MalwareUPPERCUT | UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation. |
| T1574.001 DLL |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes. |
| T1574.001 DLL |
ToolEmpire | Empire contains modules that can discover and exploit various DLL hijacking opportunities. |
| T1574.001 DLL |
ToolBrute Ratel C4 | Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.