Malicious Phantom DLL Hijacking of wlbsctrl or TSMSISrv Loaded by svchost

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects svchost.exe loading wlbsctrl.dll or TSMSISrv.dll, which are non-present phantom DLLs abused for hijacking. In the PassiveNeuron campaign attackers placed malicious copies of these DLLs so that svchost would load their implant during service startup. Because these libraries are not shipped by default Windows in the search path svchost uses, their presence indicates phantom DLL hijacking for stealthy persistence and privilege escalation.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious Phantom DLL Hijacking of oci.dll Loaded by msdtc
Suspicious HelloNet wtsapi32.dll Sideload via itcsrvup64.exe (via image_load)
Suspicious DLL Sideloading of libpython by evteng
Suspicious DLL Hijack via BugSplatRc64 Sideloading (via image_load)
Malicious USERENV.dll Sideloaded by AppVShNotify.exe
Malicious CiscoSparkLauncher DLL Sideload From AppData via image_load
Suspicious Side-Loaded D3D12_1core DLL Loaded by BellaCPP
Malicious ESET Scanner Version DLL Sideloading via image_load
Suspicious libEGL.dll Side-Loading from Public Libraries Directory (via image_load)
Malicious Phantom DLL Hijacking of wlbsctrl or TSMSISrv Loaded by svchost
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.