Malicious AppDomainManager Injection via MyAppDomainManager DLL Load

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-05-11
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects a .NET process loading a module named MyAppDomainManager.dll, the hijack DLL used by CL-STA-1062 to abuse the AppDomainManager configuration in chrome_setup.exe.config and run the TinyRCT backdoor inside a trusted process. Catching this load reveals CLR AppDomainManager injection used for defense evasion and stealthy code execution.

Related detections2 linkedT1574.014 — drag to rearrange
Renamed DLL Sideloading of TOTPGuard via Renamed Setup Binary in Nimbus Manticore Chain (via image_load)
Possible AppDomainManager Hijack via Application Config File (via file_event)
Malicious AppDomainManager Injection via MyAppDomainManager DLL Load
Pivot detection · T1574.014 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.