Suspicious jli.dll Sideloading by Non-Java Trusted Binary

PremiumReviewedSigma · Medium · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects loading of jli.dll from a user-writable or temporary directory, the DLL sideloading vector observed in the Matanbuchus and AstarionRAT chain where a signed Java launcher was abused to load a malicious jli.dll. Placing an attacker DLL beside a trusted executable causes it to be loaded with the host binary's trust. Loading jli.dll from outside a legitimate Java runtime path indicates search-order hijacking.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious DLL Sideload via SentinelBrowserNativeHost
Suspicious version.dll Sideloading via ADExplorer
Suspicious Application Config File Dropped Beside Trusted .NET Binary for App Domain Manager Injection
Suspicious Acrobat.exe Loading Co-located DLL from ProgramData
Suspicious IntelAudioService Execution with StateRepository Arguments via SPECTRALVIPER
Malicious Kazuar DLL Side-Loading via Renamed Host Binaries
Malicious Lazarus DLL Side-Loading via Colorcpl from ProgramData (via process_creation)
Malicious Lazarus DLL Side-Loading via PresentationHost from Non-Standard Path (via process_creation)
Suspicious msvc_4.dll Side-Load from Typosquatted NVIDlA Directory via Image Load
Suspicious jli.dll Sideloading by Non-Java Trusted Binary
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.