Malicious DLL Side-Loading by 3CX Desktop Application (via image_load)

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the 3CX desktop application loading ffmpeg.dll or d3dcompiler_47.dll from its own directory, the side-loading chain used in the supply chain compromise. The trojanized ffmpeg first stage and d3dcompiler decryptor run under the trusted signed 3CX process to stage second-stage shellcode.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious Child Process Spawned by 3CXDesktopApp via Supply Chain Compromise
Suspicious MsMpEng Execution from Non-Standard Directory
Malicious SUNBURST Named Pipe Creation
Malicious easinvoker.exe DLL Hijack from Public Libraries (via process_creation)
Malicious NsBars.dll Side-Loaded by Textoescritor.exe (via image_load)
Malicious WindowsCodecs.dll Side-Loaded by calc.exe (via image_load)
Malicious version.dll Side-Loaded by explorer.exe (via image_load)
Suspicious Node Package Install Spawning Script Interpreters via process_creation
Suspicious DLL Sideloading via FMAPP Executable from Non-Standard Path via process_creation
Malicious DLL Side-Loading by 3CX Desktop Application (via image_load)
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.