Malicious DLL Side-Loading of Avk.dll by G DATA Binary via PlugX (via image_load)

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the G DATA Avk.exe binary loading an Avk.dll from the Users Public GDatas directory, the side-loading step that decrypts and injects the PlugX payload. Genuine G DATA installations load their DLLs from the protected Program Files location.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious DLL Side-Loading via Remote Desktop Binaries for DreamLoaders (via image_load)
Malicious DLL Side-Loading of appvisvsubsystems64.dll via Cobalt Strike Loader (via image_load)
Suspicious Process Execution From Windows Tasks Directory
Malicious CiscoCollabHost Execution From AppData Path via process_creation
Malicious ViPNet Backdoor Loader via lumpdiag.exe Path Substitution
Suspicious msinfo32.exe Executed From ViPNet Update Directory
Suspicious DLL Side-Loading Host Binary Executed Outside System32 by Lazarus
Suspicious RC4 DLL Sideloading via rundll32 by Tropic Trooper
Malicious DLL Sideloading via Renamed Signed Binary PlayVideoFull (via process_creation)
Malicious DLL Side-Loading of Avk.dll by G DATA Binary via PlugX (via image_load)
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.