Suspicious Outlook Security Manager DLL Load for Mail Harvesting (via image_load)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-06-26
Updated
2026-08-28

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the Grandoreiro banking trojan loading the secman or secman64 Outlook Security Manager component to iterate mailbox folders and harvest addresses for spam propagation. These third-party COM libraries are rarely present on standard endpoints. Their appearance alongside Outlook automation indicates mailbox collection.

Related detections3 linkedT1114.001 — drag to rearrange
Suspicious Copy of Outlook OST Email Data File for Exfiltration
Malicious Outlook Process Memory Dump via procdump
Windows PowerShell Script Block Local Email Collection via Outlook COM Automation
Suspicious Outlook Security Manager DLL Load for Mail Harvesting (via image_load)
Pivot detection · T1114.001 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.