{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/sodinokibi/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["REvil","Sodinokibi","GOLD SOUTHFIELD"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows Defender"],"_cs_severities":["high"],"_cs_tags":["ransomware","persistence","defense-evasion","side-loading"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe REvil ransomware threat group leverages a DLL side-loading technique to achieve persistence and facilitate code execution. Attackers drop malicious versions of the Windows Defender binaries 'msmpeng.exe' (the Antimalware Service Executable) or 'mpsvc.dll' (the Antimalware Service Library) into unauthorized file system locations. By placing these files outside of the protected 'C:\\Program Files\\Windows Defender' or 'WinSxS' directories, the threat actor forces the operating system to load the malicious library instead of the legitimate one when the service is invoked. This tactic is used to evade security monitoring, as the malicious activity appears to originate from a trusted Microsoft binary. Successful exploitation allows for the deployment of ransomware, leading to broad data encryption, system compromise, and significant extortion risks. This behavior has been observed in campaigns targeting enterprise organizations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains initial access to the target environment via compromised credentials or exploit.\u003c/li\u003e\n\u003cli\u003eThe attacker performs internal reconnaissance to identify writable directories outside of System32 or protected program paths.\u003c/li\u003e\n\u003cli\u003eThe attacker drops a malicious library, 'mpsvc.dll', or a renamed executable, 'msmpeng.exe', into the identified writable directory.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes persistence by modifying registry keys or creating services to point to the malicious binary location.\u003c/li\u003e\n\u003cli\u003eThe OS initiates the side-loading process when the malicious executable is triggered or the service is restarted.\u003c/li\u003e\n\u003cli\u003eThe legitimate binary loads the malicious 'mpsvc.dll' from the attacker-controlled folder due to DLL search order hijacking.\u003c/li\u003e\n\u003cli\u003eThe payload executes in the context of the high-privileged Antimalware Service process.\u003c/li\u003e\n\u003cli\u003eFinal objective: Ransomware deployment, file encryption, and exfiltration of sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful execution of this attack leads to the deployment of the REvil ransomware payload. The impact includes the encryption of critical business data, full system compromise, exfiltration of sensitive corporate information, and the threat of double extortion. Historical attacks associated with this technique have resulted in the disruption of critical infrastructure and widespread business outages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eEnable Sysmon Event ID 11 (FileCreate) across the endpoint fleet to identify suspicious file creation events.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for 'msmpeng.exe' or 'mpsvc.dll' creation events in unauthorized paths.\u003c/li\u003e\n\u003cli\u003eUse EDR solutions to alert on child processes spawned by instances of 'msmpeng.exe' that deviate from standard behavior.\u003c/li\u003e\n\u003cli\u003eRestrict write permissions on directories that are commonly used for side-loading, such as temporary folders or user-writable application data paths.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-17T18:37:05Z","date_published":"2026-08-17T18:37:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-msmpeng-dll-sideloading/","summary":"The REvil ransomware group employs DLL side-loading to bypass security controls by placing malicious 'msmpeng.exe' or 'mpsvc.dll' files in non-standard directories to execute payloads.","title":"REvil Ransomware DLL Side-Loading via Msmpeng.exe","url":"https://feed.craftedsignal.io/briefs/2026-08-msmpeng-dll-sideloading/"}],"language":"en","title":"CraftedSignal Threat Feed - Sodinokibi","version":"https://jsonfeed.org/version/1.1"}