Threats Tagged 'dll hijacking'
View all threats tagged with 'dll hijacking'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'dll hijacking'
Click on any threat for detailed analysis and mitigation recommendations
The Iranian-linked cyber-espionage group Tortoiseshell has expanded its malware toolkit with a new reverse SSH tunneling utility disguised as wtsapi32.dll and a C++ backdoor similar to TWOSTROKE malware. The SSH tunnel uses the Windows OpenSSH client to connect to command-and-control servers. The backdoor supports executing files, shell commands, in-memory DLL execution, and file manipulation. Infrastructure analysis shows domains linked to multiple countries including the UAE, Saudi Arabia, UK, Belgium, Canada, Australia, Japan, and the United States, indicating broader targeting beyond the Middle East and US defense and military sectors. The group has been active since 2018 and maintains persistent infrastructure despite domain suspensions. No known exploits in the wild or patches are reported. Join the discussion | AlienVault OTX General | 08/26/2026, 17:18:24 UTC Added: 08/26/2026, 18:37:18 UTC |
An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives. Join the discussion | AlienVault OTX General | 06/16/2026, 05:29:40 UTC Added: 06/16/2026, 16:45:15 UTC |
A sophisticated multi-stage malware campaign targets victims through tax-themed phishing emails impersonating Indian and Japanese government authorities. The operation leverages social engineering, fraudulent tax notifications, and trusted third-party email delivery services to distribute ZIP archives containing three staged payloads. The malware implements advanced evasion techniques including DLL Search Order Hijacking, API hooking, token manipulation, Mersenne Twister-based execution logic, COM callback execution, mutated RC4 encryption, and reflective PE loading. Execution occurs primarily in memory, significantly reducing forensic artifacts. The malware establishes persistent WebSocket-based command-and-control communication through HTTP protocol upgrades, allowing malicious traffic to blend with legitimate activity. Chinese-language artifacts were observed throughout the infrastructure and code, though attribution remains at moderate confidence. The campaign demonstrates characteristics of a mature, ... MediumCampaign Join the discussion | AlienVault OTX General | 06/04/2026, 22:52:20 UTC Added: 06/05/2026, 06:33:37 UTC |
A sophisticated campaign by the Chinese APT group Silver Fox is targeting Indian entities with authentic-looking Income Tax phishing lures. The attack leverages a complex kill chain involving DLL hijacking and the modular Valley RAT to ensure persistence. The campaign uses a multi-stage infection process, starting with a malicious email containing a PDF decoy. The payload is delivered through an NSIS installer, which drops a legitimate Thunder.exe binary and a malicious libexpat.dll for DLL hijacking. The final stage involves the Valley RAT, which uses a two-stage configuration loading mechanism and implements a 3-tier C2 communication loop. The RAT's modular plugin architecture allows for dynamic capability extension and persistence through registry-based storage. Join the discussion | AlienVault OTX General | 12/24/2025, 21:10:40 UTC Added: 12/26/2025, 10:02:55 UTC |
A new campaign targeting telecommunications and manufacturing sectors in Central and South Asian countries has been discovered, delivering a new variant of PlugX. The campaign, active since 2022, shows overlaps between RainyDay and Turian backdoors, including the abuse of legitimate applications for DLL sideloading and shared encryption methods. The new PlugX variant's configuration format resembles that of RainyDay, suggesting attribution to Naikon. Analysis of victimology and technical implementation indicates a potential connection between Naikon and BackdoorDiplomacy, possibly sourcing tools from the same vendor. The malware families use similar infection chains, loaders, and shellcode structures, with shared RC4 keys for payload decryption. This campaign highlights the evolving tactics of Chinese-speaking threat actors and the potential collaboration between previously distinct groups. Join the discussion | AlienVault OTX General | 09/25/2025, 19:15:17 UTC Added: 09/25/2025, 19:26:40 UTC |
A campaign targeting telecommunications and manufacturing sectors in Central and South Asian countries has been discovered, delivering a new PlugX variant. The campaign, active since 2022, shows overlaps with RainyDay and Turian backdoors, including the abuse of legitimate applications for DLL sideloading and shared encryption methods. The new PlugX variant's configuration format resembles that of RainyDay, suggesting attribution to Naikon. Analysis of victimology and technical implementation indicates a potential connection between Naikon and BackdoorDiplomacy, possibly sourcing tools from the same vendor. The malware families use similar infection chains, loaders, and shellcode structures, with shared RC4 keys for payload decryption. This campaign highlights the evolving tactics of Chinese-speaking threat actors and the potential convergence of previously distinct groups. Join the discussion | AlienVault OTX General | 09/23/2025, 22:15:40 UTC Added: 09/24/2025, 12:30:16 UTC |
A sophisticated cyberattack campaign targeted the Russian IT industry and other entities globally in late 2024. The attackers used social media profiles and popular websites to deliver payload information, bypassing detection methods. They employed spear phishing emails with malicious RAR archives, exploiting DLL hijacking techniques to deploy Cobalt Strike Beacon. The campaign used profiles on GitHub, Microsoft Learn Challenge, Quora, and Russian social networks to conceal activities. The attacks primarily focused on Russian companies but also affected organizations in China, Japan, Malaysia, and Peru. The complexity of the methods used highlights the evolving tactics of threat actors in concealing well-known tools and emphasizes the need for robust cybersecurity measures. Join the discussion | AlienVault OTX General | 07/30/2025, 14:41:26 UTC Added: 07/30/2025, 14:47:50 UTC |
Showing 1 to 7 of 7 results