Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.001 DLL |
GroupSideCopy | SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`. |
| T1574.001 DLL |
GroupGALLIUM | GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine. |
| T1574.001 DLL |
GroupAPT3 | APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools. |
| T1574.001 DLL |
GroupPatchwork | A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading. |
| T1574.001 DLL |
GroupAPT41 | APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware. |
| T1574.001 DLL |
GroupEvilnum | Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
| T1574.001 DLL |
GroupAPT32 | APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder). |
| T1574.001 DLL |
GroupMuddyWater | MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware. |
| T1574.001 DLL |
GroupNaikon | Naikon has used DLL side-loading to load malicious DLL's into legitimate executables. |
| T1574.001 DLL |
GroupStorm-1811 | Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload. |
| T1574.001 DLL |
GroupSidewinder | Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.001 DLL |
GroupHigaisa | Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the |
| T1574.001 DLL |
GroupTropic Trooper | Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools. |
| T1574.001 DLL |
GroupAquatic Panda | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| T1574.001 DLL |
GroupBlackTech | BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories. |
| T1574.001 DLL |
GroupCinnamon Tempest | Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs. |
| T1574.001 DLL |
GroupChimera | Chimera has used side loading to place malicious DLLs in memory. |
| T1574.001 DLL |
GroupMirrorFace | MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading. |
| T1574.001 DLL |
GroupBRONZE BUTLER | BRONZE BUTLER has used legitimate applications to side-load malicious DLLs. |
| T1574.001 DLL |
GroupBackdoorDiplomacy | BackdoorDiplomacy has executed DLL search order hijacking. |
| T1574.001 DLL |
GroupWhitefly | Whitefly has used search order hijacking to run the loader Vcrodat. |
| T1574.001 DLL |
GroupLuminousMoth | LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware. |
| T1574.001 DLL |
GroupRTM | RTM has used search order hijacking to force TeamViewer to load a malicious DLL. |
| T1574.001 DLL |
GroupAPT-C-36 | APT-C-36 has used side-loading to execute the HijackLoader payload. |
| T1574.001 DLL |
GroupTonto Team | Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL. |
| T1574.001 DLL |
GroupLazarus Group | Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`. |
| T1574.001 DLL |
GroupEarth Lusca | Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service. |
| T1574.001 DLL |
GroupVelvet Ant | Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX. |
| T1574.001 DLL |
GroupDaggerfly | Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity. |
| T1574.001 DLL |
GroupWIRTE | WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading. |
| T1574.001 DLL |
GroupThreat Group-3390 | Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler. |
| T1574.001 DLL |
GroupFIN13 | FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507). |
| T1574.001 DLL |
GroupAPT19 | APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.