1200KM / simulation
T1574.001 DLL — Attack Simulation
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking. Specific ways DLLs are abused by adversaries include: ### DLL…
Technique description
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking. Specific ways DLLs are abused by adversaries include: ### DLL…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Phantom Dll Hijacking - WinAppXRT.dll
Procedure 46ed938b-c617-429a-88dc-d49b5c9ffedb; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Phantom Dll Hijacking - ualapi.dll
Procedure 5898902d-c5ad-479a-8545-6f5ab3cfc87f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- DLL Side-Loading using the Notepad++ GUP.exe binary
Procedure 65526037-7079-44a9-bda1-2cb624838040; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- DLL Search Order Hijacking - amsi.dll
Procedure 8549ad4b-b5df-4a2d-a3d7-2aee9e7052a3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- DLL Search Order Hijacking,DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
Procedure c095ad8e-4469-4d33-be9d-6f6d1fb21585; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- DLL Side-Loading using the dotnet startup hook environment variable
Procedure d322cdd7-7d60-46e3-9111-648848da7c02; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- DLL Search Order Hijacking - ntprint
Procedure e96b8105-d7f7-484e-8d81-2d0c7086971b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Naikon · G0019
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Patchwork · G0040
- menuPass · G0045
- RTM · G0048
- APT32 · G0050
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- WIRTE · G0090
- GALLIUM · G0093
- APT41 · G0096
- BlackTech · G0098
- APT-C-36 · G0099
- Whitefly · G0107
- Chimera · G0114
- Evilnum · G0120
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- Tonto Team · G0131
- BackdoorDiplomacy · G0135
- Aquatic Panda · G0143
- Earth Lusca · G1006
- SideCopy · G1008
- LuminousMoth · G1014
- FIN13 · G1016
- Cinnamon Tempest · G1021
- Daggerfly · G1034
- Storm-1811 · G1046
- Velvet Ant · G1047
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.