Suspicious DLL Side-Loading Host Binary Executed Outside System32 by Lazarus

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects execution of signed host binaries such as CameraSettingsUIHost.exe or Dxpserver.exe from directories outside the Windows System32 path. The Lazarus group side-loads malicious DLLs (DUI70.dll, dwmapi.dll) by placing these legitimate executables in attacker-controlled folders. A trusted binary running from an unexpected location indicates a DLL search-order hijack.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious RC4 DLL Sideloading via rundll32 by Tropic Trooper
Malicious DLL Sideloading via Renamed Signed Binary PlayVideoFull (via process_creation)
Suspicious obs-browser-page.exe Executing Outside OBS Installation Path (via process_creation)
Suspicious McAfee DLL Sideload via mcods Process Creation
Malicious Phantom DLL Hijacking of oci.dll Loaded by msdtc
Suspicious HelloNet wtsapi32.dll Sideload via itcsrvup64.exe (via image_load)
Suspicious DLL Sideloading of libpython by evteng
Suspicious DLL Hijack via BugSplatRc64 Sideloading (via image_load)
Malicious Phantom DLL Hijacking of wlbsctrl or TSMSISrv Loaded by svchost
Suspicious DLL Side-Loading Host Binary Executed Outside System32 by Lazarus
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.