T1574.001 DLL — ATT&CK Technique
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking. Specific ways DLLs are abused by adversaries include: ### DLL Sideloading Adversaries may execute their own malicious payloads by side-loading DLLs. Side-loading involves hijacking which DLL a program loads by planting and then invoking a legitimate application that executes their payload(s). Side-loading positions both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process. Adversaries may also side-load other packages, such as BPLs (Borland Package Library). Adversaries may chain DLL sideloading multiple times to fragment functionality hindering analysis. Adversaries using multiple DLL files can split the loader functions across different DLLs, with a main DLL loading the separated export functions. Spreading loader functions across multiple DLLs makes analysis harder, since all files must be collected to fully understand the malware’s behavior. Another method implements a “loader-for-a-loader”, where a malicious DLL’s sole role is to load a second DLL (or a chain of DLLs) that contain the real payload. ### DLL Search Order Hijacking Adversaries may execute their own malicious payloads by hijacking the search order that Windows uses to load DLLs. This search order is a sequence of special and standard search locations that a program checks when loading a DLL. An adversary can plant a trojan DLL in a directory that will be prioritized by the DLL search order over the location of a legitimate library. This will cause Windows to load the malicious DLL when it is called for by the victim program. ### DLL Redirection Adversaries may directly modify the search order via DLL redirection, which after being enabled (in the Registry or via the creation of a redirection file) may cause a program to load a DLL from a different location. ### Phantom DLL Hijacking Adversaries may leverage phantom DLL hijacking by targeting references to non-existent DLL files. They may be able to load their own malicious DLL by planting it with the correct name in the location of the missing module. ### DLL Substitution Adversaries may target existing, valid DLL files and substitute them with their own malicious DLLs, planting them with the same name and in the same location as the valid DLL file. Programs that fall victim to DLL hijacking may appear to behave normally because malicious DLLs may be configured to also load the legitimate DLLs they were meant to replace, evading defenses. Remote DLL hijacking can occur when a program sets its current directory to a remote location, such as a Web share, before loading a DLL. If a valid DLL is configured to run at a higher privilege level, then the adversary-controlled DLL that is loaded will also be executed at the higher level. In this case, the technique could be used for privilege escalation.
Detection coverage (50)
- DLL Names Used By SVR For GraphicalProton Backdoor medium
- Lazarus APT DLL Sideloading Activity high
- Diamond Sleet APT DLL Sideloading Indicators high
- Potential Raspberry Robin Aclui Dll SideLoading high
- Use Of Hidden Paths Or Files low
- DNS Server Error Failed Loading the ServerLevelPluginDLL high
- Microsoft Defender Blocked from Loading Unsigned DLL high
- Unsigned Binary Loaded From Suspicious Location high
- DHCP Server Error Failed Loading the CallOut DLL high
- DHCP Server Loaded the CallOut DLL high
- Creation Of Non-Existent System DLL medium
- DLL Search Order Hijackig Via Additional Space in Path high
- Malicious DLL File Dropped in the Teams or OneDrive Folder high
- HackTool - Powerup Write Hijack DLL high
- Potential Initial Access via DLL Search Order Hijacking medium
- Creation of WerFault.exe/Wer.dll in Unusual Folder medium
- Potential Azure Browser SSO Abuse low
- Unsigned .node File Loaded medium
- Potential Antivirus Software DLL Sideloading medium
- Potential CCleanerReactivator.DLL Sideloading medium
- System Control Panel Item Loaded From Uncommon Location high
- Potential Edputil.DLL Sideloading high
- Aruba Network Service Potential DLL Sideloading high
- Potential DLL Sideloading Via ClassicExplorer32.dll medium
- Potential AVKkid.DLL Sideloading medium
- Potential DLL Sideloading Via comctl32.dll high
- Potential DLL Sideloading Of DbgModel.DLL medium
- Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE medium
- Potential appverifUI.DLL Sideloading high
- Potential Chrome Frame Helper DLL Sideloading medium
- Potential DLL Sideloading Of DBGCORE.DLL medium
- Potential System DLL Sideloading From Non System Locations high
- Potential DLL Sideloading Via JsSchHlp medium
- Potential 7za.DLL Sideloading low
- Potential CCleanerDU.DLL Sideloading medium
- Potential EACore.DLL Sideloading high
- Potential Iviewers.DLL Sideloading high
- Potential Mfdetours.DLL Sideloading medium
- Potential DLL Sideloading Of Non-Existent DLLs From System Folders high
- Potential DLL Sideloading Of DBGHELP.DLL medium
- Potential Goopdate.DLL Sideloading medium
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE high
- Potential DLL Sideloading Of MpSvc.DLL medium
- Potential RjvPlatform.DLL Sideloading From Non-Default Location high
- Potential SolidPDFCreator.DLL Sideloading medium
- Potential Vivaldi_elf.DLL Sideloading medium
- Potential Waveedit.DLL Sideloading high
- Potential JLI.dll Side-Loading high
- Potential Rcdll.DLL Sideloading high
- Potential ShellDispatch.DLL Sideloading medium
Malware using this technique
- Ninja
- RCSession
- IronWind
- Downdelph
- Chinoxy
- PAKLOG
- RedLeaves
- Havoc
- WEBC2
- Nebulae
- TONESHELL
- RainyDay
- Ecipekac
- BOOKWORM
- Clambling
- Prikormka
- PUBLOAD
- CANONSTAGER
- LoFiSe
- WastedLocker
- InvisiMole
- CLAIMLOADER
- ZeroT
- Raspberry Robin
- HUI Loader
- HyperBro
- SplatDropper
- Javali
- BBSRAT
- PlugX
- NOOPLDR
- Lumma Stealer
- DarkGate
- FoggyWeb
- Melcoz
- Chaes
- LODEINFO
- Metamorfo
- HTTPBrowser
- T9000
- gh0st RAT
- Kerrdown
- Crutch
- Hikit
- StrelaStealer
- Sakula
- CorKLOG
- Pandora
- FinFisher
- Wingbird
Threat actors using this technique
- Salt Typhoon
- Sarcoma
- Daggerfly
- WIRTE
- SideCopy
- GALLIUM
- APT3
- Patchwork
- Evilnum
- APT32
- MuddyWater
- Naikon
- APT-C-36
- Tonto Team
- Storm-1811
- Mustang Panda
- Higaisa
- Tropic Trooper
- Aquatic Panda
- BlackTech
- APT27
- Cinnamon Tempest
- Chimera
- MirrorFace
- BRONZE BUTLER
- BackdoorDiplomacy
- Whitefly
- LuminousMoth
- RTM
- Lazarus Group
- Earth Lusca
- Velvet Ant
- Sidewinder
- APT41
- APT10
- FIN13
- APT19