AppDomainManager

T1574.014

Sub-technique of T1574 Hijack Execution Flow.View on attack.mitre.org

About this technique

Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.

Known as "AppDomainManager injection," adversaries may execute arbitrary code by hijacking how .NET applications load assemblies. For example, malware may create a custom application domain inside a target process to load and execute an arbitrary assembly. Alternatively, configuration files (`.config`) or process environment variables that define .NET runtime settings may be tampered with to instruct otherwise benign .NET applications to load a malicious assembly (identified by name) into the target process.

Detection rules1

Rules on DetectionCode tagged with T1574.014.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Windows Potential AppDomainManager Hijack Artifacts CreationAnomalyNULLSysmon EventID 11

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareIMAPLoader

IMAPLoader is executed via the AppDomainManager injection technique.

References4

  1. Microsoft App Domains Open source
    Microsoft. (2021, September 15). Application domains. Retrieved March 28, 2024.
  2. PenTestLabs AppDomainManagerInject Open source
    Administrator. (2020, May 26). APPDOMAINMANAGER INJECTION AND DETECTION. Retrieved March 28, 2024.
  3. PwC Yellow Liderc Open source
    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved March 29, 2024.
  4. Rapid7 AppDomain Manager Injection Open source
    Spagnola, N. (2023, May 5). AppDomain Manager Injection: New Techniques For Red Teams. Retrieved March 29, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.