ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1574.001×

35 examples

TechniqueUsed byProcedure example
T1574.001
DLL
GroupSideCopy

SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`.

T1574.001
DLL
GroupGALLIUM

GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.

T1574.001
DLL
GroupAPT3

APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools.

T1574.001
DLL
GroupPatchwork

A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading.

T1574.001
DLL
GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

T1574.001
DLL
GroupEvilnum

Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

T1574.001
DLL
GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

T1574.001
DLL
GroupMuddyWater

MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.

T1574.001
DLL
GroupNaikon

Naikon has used DLL side-loading to load malicious DLL's into legitimate executables.

T1574.001
DLL
GroupStorm-1811

Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.

T1574.001
DLL
GroupSidewinder

Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
GroupHigaisa

Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX dynamic link library.

T1574.001
DLL
GroupTropic Trooper

Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools.

T1574.001
DLL
GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

T1574.001
DLL
GroupBlackTech

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.

T1574.001
DLL
GroupCinnamon Tempest

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs.

T1574.001
DLL
GroupChimera

Chimera has used side loading to place malicious DLLs in memory.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1574.001
DLL
GroupBRONZE BUTLER

BRONZE BUTLER has used legitimate applications to side-load malicious DLLs.

T1574.001
DLL
GroupBackdoorDiplomacy

BackdoorDiplomacy has executed DLL search order hijacking.

T1574.001
DLL
GroupWhitefly

Whitefly has used search order hijacking to run the loader Vcrodat.

T1574.001
DLL
GroupLuminousMoth

LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware.

T1574.001
DLL
GroupRTM

RTM has used search order hijacking to force TeamViewer to load a malicious DLL.

T1574.001
DLL
GroupAPT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

T1574.001
DLL
GroupTonto Team

Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL.

T1574.001
DLL
GroupLazarus Group

Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`.

T1574.001
DLL
GroupEarth Lusca

Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service.

T1574.001
DLL
GroupVelvet Ant

Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX.

T1574.001
DLL
GroupDaggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

T1574.001
DLL
GroupWIRTE

WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

T1574.001
DLL
GroupFIN13

FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).

T1574.001
DLL
GroupAPT19

APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.