Threats Tagged 'dll side-loading'
View all threats tagged with 'dll side-loading'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'dll side-loading'
Click on any threat for detailed analysis and mitigation recommendations
This analysis covers infostealer distribution trends during August 2026, focusing on distribution channels, detection rates, and disguise techniques. Primary infostealers identified include Remus, Vidar, LummaC2, and ACRStealer, distributed through crack software disguises, SEO poisoning, and file-hosting platforms like Mega and Mediafire. Malware disguised itself as legitimate companies, with Microsoft Corporation being the most frequently impersonated. Distribution methods included DLL side-loading using python37.dll and python36.dll, and exploitation of Renpy game development tool. Email campaigns delivered Formbook disguised as Turkish bank statements and AgentTesla as business quote requests from Indian companies. EXE files constituted 97.3% of execution types. The stolen information poses risks for dark web trading and secondary attacks, emphasizing the need for cautious handling of untrusted links, avoiding illegal software, enabling two-factor authentication, and maintaining updated security soluti... Join the discussion | AlienVault OTX General | 09/22/2026, 13:13:35 UTC Added: 09/23/2026, 11:33:04 UTC |
0 ESET researchers uncovered a Lazarus attack against a Spanish aerospace company where attackers masqueraded as Meta recruiters on LinkedIn, sending trojanized coding challenges to employees. The campaign deployed multiple tools including LightlessCan, a previously undocumented backdoor that mimics native Windows commands to evade detection. Initial access was achieved through spearphishing via LinkedIn Messaging, delivering malicious executables disguised as C++ programming tests. The attack chain involved DLL side-loading techniques delivering payloads including NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT supporting 68 commands. LightlessCan represents a significant advancement over its predecessor BlindingCan, implementing execution guardrails and enhanced stealth capabilities. The campaign targeted aerospace technology and know-how for cyberespionage purposes, consistent with North Korean strategic objectives in missile development. Join the discussion | AlienVault OTX General | 09/18/2026, 21:29:42 UTC Added: 09/21/2026, 08:46:37 UTC |
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims... Join the discussion | CVE Database V5 | 08/11/2026, 15:30:01 UTC Added: 06/16/2026, 20:46:48 UTC |
During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:14 UTC Added: 07/15/2026, 21:47:49 UTC |
An internal security operations team identified a fraudulent GitHub page impersonating a cybersecurity vendor to target customers and the general public. The malicious page appeared legitimate by referencing authentic services and operational requirements. While the GitHub page itself contained non-malicious content, a disguised link led victims to download a ZIP archive containing malicious executables. The attack chain deployed BoryptGrab Stealer information-stealing malware through DLL side-loading techniques. Investigation revealed nearly 300 similar repositories impersonating well-known organizations including Malwarebytes, Bitdefender, and 360 Total Security, using SEO keywords to attract victims. The malicious page has been removed and detection capabilities have been enhanced. Join the discussion | AlienVault OTX General | 07/02/2026, 16:15:21 UTC Added: 07/03/2026, 07:06:38 UTC |
This analysis covers infostealer distribution trends observed during May 2026, based on automated collection systems and diagnostic logs. Distribution occurred primarily through illegal software disguised as cracks and keygens, as well as email campaigns. ACRStealer, Remus, and LummaC2 were most prevalent, with distribution via domains including Mediafire and AWS S3 buckets. Microsoft was the most impersonated company, followed by Auslogics and NVIDIA. EXE files represented 78.9% of execution types, while DLL side-loading accounted for 21.1%. macOS environments saw ClickFix techniques and malicious Bash scripts, with 142 scripts and 12 C2 domains identified. Email campaigns distributed AgentTesla and DarkCloud. Remus showed significant growth, comprising 36% of distributions. LummaC2 remained the most prevalent overall variant. Join the discussion | AlienVault OTX General | 06/18/2026, 14:53:53 UTC Added: 06/18/2026, 20:20:24 UTC |
A new campaign has been identified utilizing a valid digital signature from a Chinese technology company that remains unrevoked. The attack chain employs a dropper that retrieves an extension-based module list from command and control infrastructure. The malicious payloads exploit DLL Side-Loading techniques through a legitimate Tencent-signed executable to achieve code execution. The infrastructure includes Google Cloud Storage and a dedicated domain for command and control operations. Multiple components have been identified including an EXE dropper, DLL loader, DAT payload, and the legitimate Tencent executable used for side-loading purposes. Join the discussion | AlienVault OTX General | 06/17/2026, 08:46:02 UTC Added: 06/17/2026, 09:01:46 UTC |
A cybercrime campaign active since at least 2022 has been distributing cryptocurrency miners and RAT malware through illegal streaming sites and digital libraries. Victims are tricked via fake video player plugin updates or browser crash pages into downloading ZIP archives containing legitimate executables and malicious DLLs. The malware employs DLL side-loading, establishes persistence through Windows services, and deploys multiple components including XMRig-based CPU miners, GPU miners, a watchdog module, and a RAT agent with remote control capabilities. The campaign leverages highly popular pirated content sites with monthly traffic reaching up to 40 million visits, significantly expanding the potential victim pool. The malware includes sophisticated anti-detection features, DNS tunneling for command-and-control, and domain generation algorithms based on dates. Join the discussion | AlienVault OTX General | 05/28/2026, 10:56:53 UTC Added: 05/28/2026, 15:18:34 UTC |
Two distinct phishing campaigns have been identified targeting companies in Greece, Spain, Slovenia, Bosnia and Central American countries to deliver FormBook data-stealing malware. The first campaign uses RAR attachments containing legitimate executables like Sandboxie ImBox.exe, TikTok desktop, Adobe PDF Preview Handler, and XZ Utils, exploiting DLL side-loading with malicious DLL files. The second campaign deploys heavily obfuscated JavaScript that drops encrypted PNG files, uses PowerShell with Base64 encoding, and leverages a custom .NET loader called Mandark to inject the payload into RegAsm process. Both campaigns deliver the same FormBook executable that employs advanced evasion by manually mapping ntdll.dll in memory to bypass user-mode monitoring and perform direct syscalls, enabling credential theft and data collection from browsers while avoiding detection mechanisms. Join the discussion | AlienVault OTX General | 04/22/2026, 12:43:19 UTC Added: 04/22/2026, 15:31:05 UTC |
An intrusion attributed to MuddyWater, an Iranian-linked APT, was identified in a customer environment. The attack involved initial access through RDP, establishing an SSH tunnel, and deploying malware via DLL side-loading. The threat actor used FMAPP.exe, a legitimate Fortemedia Inc.application, to load a malicious FMAPP.dll for C2 communications. The timeline of activities revealed typos in commands, suggesting manual typing by the attacker. The intrusion included reconnaissance efforts, attempts to verify tunnel functionality, and issues with initial C2 communication. The attack targeted an Israeli company, aligning with known MuddyWater tactics. Join the discussion | AlienVault OTX General | 03/07/2026, 09:44:29 UTC Added: 03/09/2026, 10:51:51 UTC |
Showing 1 to 10 of 21 results