35
Groups Using This
2
Tactics
1
Platforms
32
Prevalence Rank
Description

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking. Specific ways DLLs are abused by adversaries include: ### DLL Sideloading Adversaries may execute their own malicious payloads by side-loading DLLs. Side-loading involves hijacking which DLL a program loads by planting and then invoking a legitimate application that executes their payload(s). Side-loading positions both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process. Adversaries may also side-load other packages, such as BPLs (Borland Package Library). Adversaries may chain DLL sideloading multiple times to fragment functionality hindering analysis. Adversaries using multiple DLL files can split the loader functions across different DLLs, with a main DLL loading the separated export functions. Spreading loader functions across multiple DLLs makes analysis harder, since all files must be collected to fully understand the malware’s behavior. Another method implements a “loader-for-a-loader”, where a malicious DLL’s sole role is to load a second DLL (or a chain of DLLs) that contain the real payload. ### DLL Search Order Hijacking Adversaries may execute their own malicious payloads by hijacking the search order that Windows uses to load DLLs. This search order is a sequence of special and standard search locations that a program checks when loading a DLL. An adversary can plant a trojan DLL in a directory that will be prioritized by the DLL search order over the location of a legitimate library. This will cause Windows to load the malicious DLL when it is called for by the victim program. ### DLL Redirection Adversaries may directly modify the search order via DLL redirection, which after being enabled (in the Registry or via the creation of a redirection file) may cause a program to load a DLL from a different location. ### Phantom DLL Hijacking Adversaries may leverage phantom DLL hijacking by targeting references to non-existent DLL files. They may be able to load their own malicious DLL by planting it with the correct name in the location of the missing module. ### DLL Substitution Adversaries may target existing, valid DLL files and substitute them with their own malicious DLLs, planting them with the same name and in the same location as the valid DLL file. Programs that fall victim to DLL hijacking may appear to behave normally because malicious DLLs may be configured to also load the legitimate DLLs they were meant to replace, evading defenses. Remote DLL hijacking can occur when a program sets its current directory to a remote location, such as a Web share, before loading a DLL. If a valid DLL is configured to run at a higher privilege level, then the adversary-controlled DLL that is loaded will also be executed at the higher level. In this case, the technique could be used for privilege escalation.

View MITRE record ↗

Platforms
Windows
Groups Using T1574.001 (35)
G0032
Lazarus Group
🇰🇵 North Korea93 techniques26 software
G0129
Mustang Panda
🇷🇺 Russia85 techniques23 software
G0096
APT41
🇨🇳 China82 techniques32 software
G0050
APT32
🇻🇳 Vietnam78 techniques15 software
G0069
MuddyWater
🇮🇷 Iran68 techniques21 software
G0114
Chimera
🇨🇳 China59 techniques6 software
G0027
Threat Group-3390
🇨🇳 China57 techniques24 software
G1016
FIN13
53 techniques4 software
G0045
menuPass
🇨🇳 China46 techniques25 software
G1006
Earth Lusca
🇨🇳 China44 techniques9 software
G0022
APT3
🇨🇳 China44 techniques6 software
G1054
MirrorFace
🇨🇳 China43 techniques16 software
G0040
Patchwork
🇨🇳 China41 techniques8 software
G0060
BRONZE BUTLER
🇨🇳 China40 techniques14 software
G0081
Tropic Trooper
40 techniques6 software
G0099
APT-C-36
38 techniques9 software
G0143
Aquatic Panda
🇨🇳 China35 techniques6 software
G1046
Storm-1811
31 techniques7 software
G0093
GALLIUM
🇷🇺 Russia31 techniques16 software
G0121
Sidewinder
🇨🇳 China30 techniques1 software
G1014
LuminousMoth
🇨🇳 China28 techniques2 software
G0126
Higaisa
🇷🇺 Russia28 techniques3 software
G0090
WIRTE
26 techniques8 software
G1047
Velvet Ant
22 techniques2 software
G0073
APT19
🇨🇳 China21 techniques2 software
G1021
Cinnamon Tempest
🇨🇳 China19 techniques8 software
G1034
Daggerfly
🇨🇳 China17 techniques6 software
G1008
SideCopy
🇵🇰 Pakistan16 techniques2 software
G0131
Tonto Team
🇨🇳 China15 techniques6 software
G0135
BackdoorDiplomacy
15 techniques5 software
G0098
BlackTech
🇨🇳 China14 techniques6 software
G0019
Naikon
🇨🇳 China14 techniques15 software
G0120
Evilnum
11 techniques3 software
G0107
Whitefly
9 techniques1 software
G0048
RTM
🇷🇺 Russia7 techniques1 software
↑