FORENSIA

ATT&CK · T1574.001 · sub-technique

DLL

Tactics: stealth, execution

About

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking. Specific ways DLLs are abused by adversaries include: ### DLL Sideloading Adversaries may execute their own malicious payloads by side-loading DLLs. Side-loading involves hijacking which DLL a program loads by planting and then invoking a legitimate application that executes their payload(s). Side-loading positions both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process. Adversaries may also side-load other packages, such as BPLs (Borland Package Library). Adversaries may chain DLL sideloading multiple times to fragment functionality hindering analysis. Adversaries using multiple DLL files can split the loader functions across different DLLs, with a main DLL loading the separated export functions. Spreading loader functions across multiple DLLs makes analysis harder, since all files must be collected to fully understand the malware’s behavior. Another method implements a “loader-for-a-loader”, where a malicious DLL’s sole role is to load a second DLL (or a chain of DLLs) that contain the real payload. ### DLL Search Order Hijacking Adversaries may execute their own malicious payloads by hijacking the search order that Windows uses to load DLLs. This search order is a sequence of special and standard search locations that a program checks when loading a DLL. An adversary can plant a trojan DLL in a directory that will be prioritized by the DLL search order over the location of a legitimate library. This will cause Windows to load the malicious DLL when it is called for by the victim program. ### DLL Redirection Adversaries may directly modify the search order via DLL redirection, which after being enabled (in the Registry or via the creation of a redirection file) may cause a program to load a DLL from a different location. ### Phantom DLL Hijacking Adversaries may leverage phantom DLL hijacking by targeting references to non-existent DLL files. They may be able to load their own malicious DLL by planting it with the correct name in the location of the missing module. ### DLL Substitution Adversaries may target existing, valid DLL files and substitute them with their own malicious DLLs, planting them with the same name and in the same location as the valid DLL file. Programs that fall victim to DLL hijacking may appear to behave normally because malicious DLLs may be configured to also load the legitimate DLLs they were meant to replace, evading defenses. Remote DLL hijacking can occur when a program sets its current directory to a remote location, such as a Web share, before loading a DLL. If a valid DLL is configured to run at a higher privilege level, then the adversary-controlled DLL that is loaded will also be executed at the higher level. In this case, the technique could be used for privilege escalation.

Used by actors

35 known groups

Software

75 malware/tools implement this

HikitPlugXgh0st RATHTTPBrowserSakulaT9000WEBC2PrikormkaBBSRATBADNEWSDowndelphRedLeavesWingbirdFinFisherPowerSploitZeroTInvisiMoleUPPERCUTMirageFoxDenisEmpireAstarothDridexHyperBroBOOSTWRITEMetamorfoRamsayGoopyJavaliMelcozCrutchEgregorWaterbearLookBackKerrdownWastedLockerEcipekacRainyDayNebulaeChaesQakBotClamblingFoggyWebRCSessionSysUpdatePandoraChinoxyPowGoopmetaMainBrute Ratel C4HUI LoaderNinjaLoFiSePcexterDarkGateRaspberry RobinStrelaStealerLumma StealerBOOKWORMStarProxyPUBLOADHavocHIUPANSplatDropperPAKLOGCorKLOGCLAIMLOADERCANONSTAGERTONESHELLLODEINFONOOPLDRROAMINGHOUSEANELLDRIronWindAshTag

Corpus indicators tagged with this technique

49 indicators in the corpus carry T1574.001.

IndicatorTypeFamilySevSrc
87d4c8d022a298cefcb113040e69934d5be6a91chashphishing802
4c9061a07d667bf7dd6f597a43a8552af2f4277b7be06d6ea138abdb668d6a49hashphishing802
103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0sha256supply_chain801
4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affesha256supply_chain801
9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9sha256supply_chain801
7d87a86dbd2379ef2516c99258137cd9c25ca19c48aeb096c5332c02fcbf16d0hashphishing802
e83ff54e58f0b295a392c7fc39a7d0dehashphishing802
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801
3a8f6454927b8993aded75de0de2bd00hashphishing802
4650f7dc1a2ddbb6d73bf5bfd1b69dd6b79e0cddhashphishing802
185b7a487316454da04e9cc0fe6eb370bb2955cf6096fe3e8c02c46f8989ba37hashphishing802
be31a63cad112723178289968ad6f93a576c5a7984099c42eec3521cdf6e5fc0hashphishing802
b498256cb086a6962077cdd6d2f65327hashphishing802
949acbe543fc244ffbc981ea169067da7c5792af3c3d19b2c31b3d7e19106880hashphishing802
191f6b9a3bc7f0f01c6aaae6485b7bf85e6c12f4sha1supply_chain781
a7d7d6c4c3f227f7117261c63b9e23a9md5761
7bd07e4d557852446a284d038fa0ed0emd5supply_chain761
9f5f2f0fb0a7f5aa9f16b9a7b6dad89fmd5761
28cb7b261f4eb97e8a4b3b0d32f8def1md5761
1ab58838e5790efb22f2d35ab98c0b7dmd5761
22aaeb4946ba6d2f2e27feb7dbb295demd5761
3432dd9ac0df80ef86eb80bd080f839bmd5761
3d3a621f852c42d97fd7260681e42508md5761
bae82a15d1dbfb024617b9b56a8e5f66md5761
f169d6d172dfb775895a5e2b1540c854md5761

Showing the top 30 by severity of 49.