Suspicious wlbsctrl.dll Sideloading via IKEEXT Service

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects svchost loading wlbsctrl.dll from outside System32, a phantom-DLL sideloading path abused via the IKEEXT service to run attacker code in the incident-response cases. Because wlbsctrl.dll is normally absent from the system, a service loading it from a non-System32 location indicates persistence via DLL hijacking.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious Service DLL Hijack of IKEEXT or PrintNotify
Suspicious Impact of 'SMOKEDHAM Backdoor' with MSDTC Service Privilege Escalation via Command Line (via process_creation)
Malicious USERENV.dll Sideloaded by AppVShNotify.exe
Malicious CiscoSparkLauncher DLL Sideload From AppData via image_load
Suspicious Side-Loaded D3D12_1core DLL Loaded by BellaCPP
Malicious ESET Scanner Version DLL Sideloading via image_load
Suspicious libEGL.dll Side-Loading from Public Libraries Directory (via image_load)
Suspicious Side-Loading of wbemcomn.dll or ESENT.dll from Non-System Path (via image_load)
Suspicious adhapl Service DLL Dropped in System32 by BellaCPP
Suspicious wlbsctrl.dll Sideloading via IKEEXT Service
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.