Renamed DLL Sideloading of TOTPGuard via Renamed Setup Binary in Nimbus Manticore Chain (via image_load)

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-09-01
Updated
2026-09-01

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects a setup.exe process loading TOTPGuard.dll, the AppDomain-hijacking DLL sideloading pair used by Nimbus Manticore to run a decrypted native implant from a renamed Microsoft Visual Studio host binary. Adversaries leverage sideloading through a signed executable to execute malicious code under a trusted process, making early detection critical for surfacing the infection chain before beacon establishment.

Related detections2 linkedT1574.014 — drag to rearrange
Possible AppDomainManager Hijack via Application Config File (via file_event)
Malicious AppDomainManager Injection via MyAppDomainManager DLL Load
Renamed DLL Sideloading of TOTPGuard via Renamed Setup Binary in Nimbus Manticore Chain (via image_load)
Pivot detection · T1574.014 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.