Windows DLL Sideloading via ImageLoaded from ProgramShared, ProgramData, and ARM paths

Alerts on Windows processes loading DLLs from targeted ProgramShared/ProgramData paths consistent with DLL sideloading.

FreeUnreviewedSigmahighv1
title: Windows DLL Sideloading via ImageLoaded from ProgramShared, ProgramData, and ARM paths
id: 7a2fcf7f-c1a3-4f1d-8835-7735a7b3702d
status: test
description: This rule flags DLL sideloading behavior where a legitimate-looking EXE loads a DLL from specific, uncommon disk locations under ProgramShared, ProgramData, Oracle Java, and Adobe ARM directories. Such activity can indicate an attacker placing trojanized DLLs to hijack process execution without altering the original executable. Detection relies on image load telemetry showing the Image path and the corresponding ImageLoaded value matched by the rule’s known pairs.
references:
  - https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
  - https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Lazarus/image_load_apt_lazarus_side_load_activity.yml
author: Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-10-18
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.t1574.001
  - attack.g0032
  - detection.emerging-threats
logsource:
  product: windows
  category: image_load
detection:
  selection_mscoree:
    Image: C:\ProgramShared\PresentationHost.exe
    ImageLoaded: :\ProgramShared\mscoree.dll
  selection_colorui:
    Image: C:\ProgramData\Adobe\colorcpl.exe
    ImageLoaded: C:\ProgramData\Adobe\colorui.dll
  selection_mapistub:
    Image: C:\ProgramData\Oracle\Java\fixmapi.exe
    ImageLoaded: C:\ProgramData\Oracle\Java\mapistub.dll
  selection_hid:
    Image: C:\ProgramData\Adobe\ARM\tabcal.exe
    ImageLoaded: C:\ProgramData\Adobe\ARM\HID.dll
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 24007168-a26b-4049-90d0-ce138e13a5cf
    type: derived

What it detects

This rule flags DLL sideloading behavior where a legitimate-looking EXE loads a DLL from specific, uncommon disk locations under ProgramShared, ProgramData, Oracle Java, and Adobe ARM directories. Such activity can indicate an attacker placing trojanized DLLs to hijack process execution without altering the original executable. Detection relies on image load telemetry showing the Image path and the corresponding ImageLoaded value matched by the rule’s known pairs.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.