Sub-technique of T1574 Hijack Execution Flow.View on attack.mitre.org
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Specific ways DLLs are abused by adversaries include:
### DLL Sideloading
Adversaries may execute their own malicious payloads by side-loading DLLs. Side-loading involves hijacking which DLL a program loads by planting and then invoking a legitimate application that executes their payload(s).
Side-loading positions both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process.
Adversaries may also side-load other packages, such as BPLs (Borland Package Library).
Adversaries may chain DLL sideloading multiple times to fragment functionality hindering analysis. Adversaries using multiple DLL files can split the loader functions across different DLLs, with a main DLL loading the separated export functions. Spreading loader functions across multiple DLLs makes analysis harder, since all files must be collected to fully understand the malware’s behavior. Another method implements a “loader-for-a-loader”, where a malicious DLL’s sole role is to load a second DLL (or a chain of DLLs) that contain the real payload.
### DLL Search Order Hijacking
Adversaries may execute their own malicious payloads by hijacking the search order that Windows uses to load DLLs. This search order is a sequence of special and standard search locations that a program checks when loading a DLL. An adversary can plant a trojan DLL in a directory that will be prioritized by the DLL search order over the location of a legitimate library. This will cause Windows to load the malicious DLL when it is called for by the victim program.
### DLL Redirection
Adversaries may directly modify the search order via DLL redirection, which after being enabled (in the Registry or via the creation of a redirection file) may cause a program to load a DLL from a different location.
### Phantom DLL Hijacking
Adversaries may leverage phantom DLL hijacking by targeting references to non-existent DLL files. They may be able to load their own malicious DLL by planting it with the correct name in the location of the missing module.
### DLL Substitution
Adversaries may target existing, valid DLL files and substitute them with their own malicious DLLs, planting them with the same name and in the same location as the valid DLL file.
Programs that fall victim to DLL hijacking may appear to behave normally because malicious DLLs may be configured to also load the legitimate DLLs they were meant to replace, evading defenses.
Remote DLL hijacking can occur when a program sets its current directory to a remote location, such as a Web share, before loading a DLL.
If a valid DLL is configured to run at a higher privilege level, then the adversary-controlled DLL that is loaded will also be executed at the higher level. In this case, the technique could be used for privilege escalation.
Rules on DetectionCode tagged with T1574.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| MSI Module Loaded by Non-System Binary | Hunting | NULL | Sysmon EventID 7 |
| Msmpeng Application DLL Side Loading | TTP | NULL | Sysmon EventID 11 |
| Windows DLL Search Order Hijacking Hunt | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Windows Event Log Security 4688 |
| Windows DLL Search Order Hijacking Hunt with Sysmon | Hunting | NULL | Sysmon EventID 7 |
| Windows DLL Search Order Hijacking with iscsicpl | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows DLL Side-Loading In Calc | TTP | NULL | Sysmon EventID 7 |
| Windows DLL Side-Loading Process Child Of Calc | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Hijack Execution Flow Version Dll Side Load | Anomaly | NULL | Sysmon EventID 7 |
| Windows Known Abused DLL Created | Anomaly | NULL | Sysmon EventID 11 |
| Windows Known Abused DLL Loaded Suspiciously | TTP | NULL | Sysmon EventID 7 |
| Windows Known GraphicalProton Loaded Modules | Anomaly | NULL | Sysmon EventID 7 |
| Windows Masquerading Explorer As Child Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Mustang Panda USB Tool Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Phantom DLL Created on Disk | TTP | NULL | Sysmon EventID 11 |
| Windows SCCM Smsexec Spawned a Suspicious Child Process | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SqlWriter SQLDumper DLL Sideload | TTP | NULL | Sysmon EventID 7 |
| Windows Unsigned DLL Side-Loading | Anomaly | NULL | Sysmon EventID 7 |
| Windows Unsigned DLL Side-Loading In Same Process Path | TTP | NULL | Sysmon EventID 7 |
| Windows Unsigned MS DLL Side-Loading | Anomaly | NULL | Sysmon EventID 7 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used side-loading to execute the HijackLoader payload. |
| GroupAPT19 | APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL. |
| GroupAPT3 | APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools. |
| GroupAPT32 | APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder). |
| GroupAPT41 | APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware. |
| GroupAquatic Panda | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has executed DLL search order hijacking. |
| GroupBlackTech | BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories. |
| Used by | Procedure example |
|---|---|
| MalwareANELLDR | ANELLDR can use DLL sideloading from a legitimate application to initiate execution. |
| MalwareAshTag | AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32. |
| MalwareAstaroth | Astaroth can launch itself via DLL Search Order Hijacking. |
| MalwareBADNEWS | BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable. |
| MalwareBBSRAT | DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper. |
| MalwareBOOKWORM | BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`. |
| MalwareBOOSTWRITE | BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll. |
| ToolBrute Ratel C4 | Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus splits functionally across multiple .dll files using export functions, such as DLLGetClassObject, to execute code from an embedded .dll file within another .dll file. AppleJeus has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence. |
| CampaignAPT41 DUST | APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used DLL search order hijacking on vulnerable applications to install PlugX payloads during RedDelta Modified PlugX Infection Chain Operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.