Tag
DLL Hijacking in FirmaCheck for Windows via Unvalidated OpenSSL Configuration
1 rule 2 TTPs 1 CVEFirmaCheck for Windows versions prior to 1.3.16 are susceptible to local privilege escalation and arbitrary code execution due to an unvalidated OpenSSL configuration file path.
Mirage Kitten Targets Middle East and Africa with New Malware
4 rules 13 TTPs 3 IOCsMirage Kitten, an advanced persistent threat (APT) group, is deploying new Windows backdoor (NightLedger) and WebSocket tunnelers (ArcBridge, BridgeHead) via spear-phishing campaigns to conduct cyber-espionage and data exfiltration against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Europe.
Vulnerability in ABB Advant Master Online Builder Allows Code Execution
1 TTP 1 CVEA vulnerability (CVE-2025-13162) exists in ABB Advant Master Online Builder products, including Control Builder A and 800xA for Advant Master, enabling an attacker with necessary local access to execute unauthorized code by exploiting an uncontrolled search path element (CWE-427) to load malicious DLLs, compromising system integrity within critical manufacturing environments.
Unauthenticated Arbitrary Code Execution in SAProuter via DLL Hijacking (CVE-2026-0487)
1 rule 1 TTP 1 CVE 2 IOCsAn unauthenticated attacker can exploit CVE-2026-0487, a vulnerability in SAProuter running on Microsoft Windows, by loading malicious DLL files from an untrusted location, allowing them to execute arbitrary code on the affected system with high impact on confidentiality, integrity, and availability.
Synology BeeDrive DLL Hijacking Vulnerability (CVE-2023-52945)
2 rules 2 TTPs 1 CVESynology BeeDrive for desktop before 1.3.2-13814 is vulnerable to an uncontrolled search path element, allowing local users to execute arbitrary code through a maliciously placed OpenSSL DLL component.
WPS Office Exploitation via DLL Hijack
2 rules 2 TTPs 2 CVEsThe rule detects the loading of a remote library by the WPS Office promecefpluginhost.exe executable, which may indicate exploitation of CVE-2024-7262 or CVE-2024-7263 via DLL hijacking abusing the ksoqing custom protocol handler.
Johnson Controls CEM AC2000 Privilege Escalation via DLL Hijacking
2 rules 1 TTPA vulnerability exists in Johnson Controls CEM AC2000 versions 12.0, 11.0, and 10.6 due to an uncontrolled search path element that could allow a standard user to escalate privileges on the host machine via DLL hijacking.
AVACAST DLL Hijacking Vulnerability (CVE-2026-7279)
2 rules 1 TTP 1 CVEA DLL hijacking vulnerability in eMPIA Technology's AVACAST (CVE-2026-7279) allows authenticated local attackers to achieve arbitrary code execution with system privileges by placing a malicious DLL in a specific directory.
Mobatek MobaXterm Home Edition Uncontrolled Search Path Vulnerability (CVE-2026-6421)
2 rules 1 TTP 1 CVECVE-2026-6421 is an uncontrolled search path vulnerability in Mobatek MobaXterm Home Edition up to version 26.1, affecting msimg32.dll, that can be exploited locally with high complexity.
MemProcFS DLL and Shared Library Hijacking Vulnerability
2 rules 3 TTPs 1 CVEMemProcFS before 5.17 is susceptible to DLL and shared-library hijacking due to unsafe library-loading patterns, allowing attackers to achieve arbitrary code execution by placing malicious libraries or manipulating the library search path.
CVE-2026-3780: Local Privilege Escalation via Untrusted Search Path in Application Installer
2 rules 1 TTP 1 CVEAn application installer vulnerable to CVE-2026-3780 runs with elevated privileges but resolves system executables and DLLs using an untrusted search path, enabling local privilege escalation by allowing a local attacker to inject malicious binaries.
Local SxS Shared Module DLL Hijacking
2 rules 2 TTPsAdversaries may abuse shared modules in local Side-by-Side (SxS) folders to execute malicious payloads by instructing the Windows module loader to load DLLs from arbitrary local paths, potentially bypassing security controls.
Potential Windows Session Hijacking via CcmExec
2 rules 1 TTPAdversaries may exploit Microsoft's System Center Configuration Manager by loading malicious DLLs into SCNotification.exe, a process associated with user notifications, potentially leading to Windows session hijacking.
Suspicious Antimalware Scan Interface DLL Creation
2 rules 1 TTPAn adversary may attempt to bypass AMSI by creating a rogue AMSI DLL in an unusual location to evade detection.
Suspicious Antimalware Scan Interface DLL Creation
2 rules 2 TTPsThe rule detects the creation of the Antimalware Scan Interface (AMSI) DLL in an unusual location, potentially indicating an attempt to bypass AMSI by loading a rogue AMSI module, a technique used for defense evasion.
Execution via Local SxS Shared Module
2 rules 2 TTPsThis rule detects the creation, modification, or deletion of DLL files within Windows SxS local folders, which could indicate an attempt to execute malicious payloads by abusing shared module loading.