Malicious DLL Side-Loading of appvisvsubsystems64.dll via Cobalt Strike Loader (via image_load)

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the AppV appvisvsubsystems64.dll being loaded from the ProgramData directory by a renamed Word binary, the side-loading step that launches a Cobalt Strike beacon. The genuine appvisvsubsystems64.dll ships only inside System32.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious DLL Side-Loading via Remote Desktop Binaries for DreamLoaders (via image_load)
Suspicious Process Execution From Windows Tasks Directory
Malicious CiscoCollabHost Execution From AppData Path via process_creation
Malicious ViPNet Backdoor Loader via lumpdiag.exe Path Substitution
Suspicious msinfo32.exe Executed From ViPNet Update Directory
Suspicious DLL Side-Loading Host Binary Executed Outside System32 by Lazarus
Suspicious RC4 DLL Sideloading via rundll32 by Tropic Trooper
Malicious DLL Sideloading via Renamed Signed Binary PlayVideoFull (via process_creation)
Suspicious obs-browser-page.exe Executing Outside OBS Installation Path (via process_creation)
Malicious DLL Side-Loading of appvisvsubsystems64.dll via Cobalt Strike Loader (via image_load)
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.