DLL

T1574.001

Sub-technique of T1574 Hijack Execution Flow.View on attack.mitre.org

About this technique

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Specific ways DLLs are abused by adversaries include:

### DLL Sideloading
Adversaries may execute their own malicious payloads by side-loading DLLs. Side-loading involves hijacking which DLL a program loads by planting and then invoking a legitimate application that executes their payload(s).

Side-loading positions both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process.

Adversaries may also side-load other packages, such as BPLs (Borland Package Library).

Adversaries may chain DLL sideloading multiple times to fragment functionality hindering analysis. Adversaries using multiple DLL files can split the loader functions across different DLLs, with a main DLL loading the separated export functions. Spreading loader functions across multiple DLLs makes analysis harder, since all files must be collected to fully understand the malware’s behavior. Another method implements a “loader-for-a-loader”, where a malicious DLL’s sole role is to load a second DLL (or a chain of DLLs) that contain the real payload.

### DLL Search Order Hijacking
Adversaries may execute their own malicious payloads by hijacking the search order that Windows uses to load DLLs. This search order is a sequence of special and standard search locations that a program checks when loading a DLL. An adversary can plant a trojan DLL in a directory that will be prioritized by the DLL search order over the location of a legitimate library. This will cause Windows to load the malicious DLL when it is called for by the victim program.

### DLL Redirection
Adversaries may directly modify the search order via DLL redirection, which after being enabled (in the Registry or via the creation of a redirection file) may cause a program to load a DLL from a different location.

### Phantom DLL Hijacking
Adversaries may leverage phantom DLL hijacking by targeting references to non-existent DLL files. They may be able to load their own malicious DLL by planting it with the correct name in the location of the missing module.

### DLL Substitution
Adversaries may target existing, valid DLL files and substitute them with their own malicious DLLs, planting them with the same name and in the same location as the valid DLL file.

Programs that fall victim to DLL hijacking may appear to behave normally because malicious DLLs may be configured to also load the legitimate DLLs they were meant to replace, evading defenses.

Remote DLL hijacking can occur when a program sets its current directory to a remote location, such as a Web share, before loading a DLL.

If a valid DLL is configured to run at a higher privilege level, then the adversary-controlled DLL that is loaded will also be executed at the higher level. In this case, the technique could be used for privilege escalation.

Detection rules99

Rules on DetectionCode tagged with T1574.001.

Sigma80

RuleLevelLog source
Aruba Network Service Potential DLL Sideloadinghighwindows / image_load
DHCP Callout DLL Installationhighwindows / registry_set
DHCP Server Error Failed Loading the CallOut DLLhighwindows / NULL
DHCP Server Loaded the CallOut DLLhighwindows / NULL
DLL Search Order Hijackig Via Additional Space in Pathhighwindows / file_event
DLL Sideloading by VMware Xfer Utilityhighwindows / process_creation
DLL Sideloading Of ShellChromeAPI.DLLhighwindows / image_load
DNS Server Error Failed Loading the ServerLevelPluginDLLhighwindows / NULL
Fax Service DLL Search Order Hijackhighwindows / image_load
HackTool - Powerup Write Hijack DLLhighwindows / file_event
Malicious DLL File Dropped in the Teams or OneDrive Folderhighwindows / file_event
Microsoft Defender Blocked from Loading Unsigned DLLhighwindows / NULL
Microsoft Office DLL Sideloadhighwindows / image_load
New DNS ServerLevelPluginDll Installedhighwindows / registry_set
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXEhighwindows / process_creation

Splunk19

RuleTypeRiskData source
MSI Module Loaded by Non-System BinaryHuntingNULLSysmon EventID 7
Msmpeng Application DLL Side LoadingTTPNULLSysmon EventID 11
Windows DLL Search Order Hijacking HuntHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
Windows DLL Search Order Hijacking Hunt with SysmonHuntingNULLSysmon EventID 7
Windows DLL Search Order Hijacking with iscsicplTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows DLL Side-Loading In CalcTTPNULLSysmon EventID 7
Windows DLL Side-Loading Process Child Of CalcAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Hijack Execution Flow Version Dll Side LoadAnomalyNULLSysmon EventID 7
Windows Known Abused DLL CreatedAnomalyNULLSysmon EventID 11
Windows Known Abused DLL Loaded SuspiciouslyTTPNULLSysmon EventID 7
Windows Known GraphicalProton Loaded ModulesAnomalyNULLSysmon EventID 7
Windows Masquerading Explorer As Child ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Mustang Panda USB Tool ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Phantom DLL Created on DiskTTPNULLSysmon EventID 11
Windows SCCM Smsexec Spawned a Suspicious Child ProcessAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups35

Show 11 more

Software75

Show 51 more

Campaigns4

Procedure examples114

Groups35

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

GroupAPT19

APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL.

GroupAPT3

APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools.

GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

GroupBackdoorDiplomacy

BackdoorDiplomacy has executed DLL search order hijacking.

GroupBlackTech

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.

View all 35 groups examples

Software75

Used byProcedure example
MalwareANELLDR

ANELLDR can use DLL sideloading from a legitimate application to initiate execution.

MalwareAshTag

AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32.

MalwareAstaroth

Astaroth can launch itself via DLL Search Order Hijacking.

MalwareBADNEWS

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.

MalwareBBSRAT

DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper.

MalwareBOOKWORM

BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`.

MalwareBOOSTWRITE

BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll.

ToolBrute Ratel C4

Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe.

View all 75 software examples

Campaigns4

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus splits functionally across multiple .dll files using export functions, such as DLLGetClassObject, to execute code from an embedded .dll file within another .dll file. AppleJeus has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence.

CampaignAPT41 DUST

APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used DLL search order hijacking on vulnerable applications to install PlugX payloads during RedDelta Modified PlugX Infection Chain Operations.

References11

  1. Hexacorn DLL Hijacking Open source
    Hexacorn. (2013, December 8). Beyond good ol’ Run key, Part 5. Retrieved August 14, 2024.
  2. Hijack DLLs CrowdStrike Open source
    falcon.overwatch.team. (2022, December 30). 4 Ways Adversaries Hijack DLLs — and How CrowdStrike Falcon OverWatch Fights Back. Retrieved January 30, 2025.
  3. Microsoft - manifests/assembly Open source
    Microsoft. (2021, January 7). Manifests. Retrieved January 30, 2025.
  4. Microsoft redirection Open source
    Microsoft. (2023, October 12). Dynamic-link library redirection. Retrieved January 30, 2025.
  5. Sophos Open source
    Gabor Szappanos. (2023, May 3). A doubled “Dragon Breath” adds new air to DLL sideloading attacks. Retrieved October 3, 2025.
  6. Virus Bulletin Open source
    Suguru Ishimaru, Hajime Yanagishita, Yusuke Niwa. (2023, October 5). Unveiling activities of Tropic Trooper 2023: deep analysis of Xiangoop Loader and EntryShell payload. Retrieved October 3, 2025.
  7. Wietze Beukema DLL Hijacking Open source
    Wietze Beukema. (2020, June 22). Hijacking DLLs in Windows. Retrieved April 8, 2025.
  8. dll pre load owasp Open source
    OWASP. (n.d.). Binary Planting. Retrieved January 30, 2025.
  9. kroll bpl Open source
    Dave Truman. (2024, June 24). Novel Technique Combination Used In IDATLOADER Distribution. Retrieved January 30, 2025.
  10. microsoft remote preloading Open source
    Microsoft. (2014, May 13). Microsoft Security Advisory 2269637: Insecure Library Loading Could Allow Remote Code Execution. Retrieved January 30, 2025.
  11. unit 42 Open source
    Tom Fakterman, Chen Erlich, & Assaf Dahan. (2024, February 22). Intruders in the Library: Exploring DLL Hijacking. Retrieved January 30, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.