Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-20
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the regsvcs.exe living-off-the-land binary being used to load and install a DLL from a UNC network path, matching SafePay ransomware deployment via regsvcs proxy execution. Attackers abuse regsvcs to run their encryptor DLL while bypassing application controls. Loading a DLL over UNC through regsvcs is not a legitimate developer workflow.

Related detections9 linkedT1218 — drag to rearrange
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Chisel Reverse Tunnel Tool Execution from Temporary Directory
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
BITS Payload Downloaded via Commandline (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Suspicious SMB DLL Lateral Movement
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Suspicious Extexport DLL Side-Loading Execution
Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
Pivot detection · T1218 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.