Malicious ESET Scanner Version DLL Sideloading via image_load

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the ESET command line scanner ecls.exe loading a version.dll from a directory other than the Windows system folders which indicates DLL search order hijacking. ToddyCat abused CVE-2024-11859 to make the ESET scanner proxy load a malicious version.dll named TCESB from an attacker path. DLL proxying through a trusted security binary is a stealthy loader technique that evades many controls.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious USERENV.dll Sideloaded by AppVShNotify.exe
Malicious CiscoSparkLauncher DLL Sideload From AppData via image_load
Suspicious Side-Loaded D3D12_1core DLL Loaded by BellaCPP
Suspicious libEGL.dll Side-Loading from Public Libraries Directory (via image_load)
Suspicious wlbsctrl.dll Sideloading via IKEEXT Service
Suspicious Side-Loading of wbemcomn.dll or ESENT.dll from Non-System Path (via image_load)
Suspicious MsMpEng Execution from Non-Standard Directory
Malicious DLL Side-Loading by 3CX Desktop Application (via image_load)
Malicious easinvoker.exe DLL Hijack from Public Libraries (via process_creation)
Malicious ESET Scanner Version DLL Sideloading via image_load
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.