Malicious Service DLL Hijack for Persistence via Lotus Blossom

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-12
Updated
2026-09-12

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects modification of the ServiceDll parameter of the legitimate TapiSrv swprv or AppMgmt services which the Lotus Blossom espionage group abuses to load its Sagerunex backdoor under a trusted service host process. Rewriting the ServiceDll of these built in services is a stealthy persistence and defense evasion technique.

Related detections9 linkedT1112 — drag to rearrange
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Windows Service Trigger Configuration via Registry Modification
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Windows Registry Persistence via UMe/UT Run Keys
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.