TACTIC: PERSISTENCE

DLL Side-Loading (T1574.002): real cases

MITRE Definition ↗
Adversaries execute malicious dynamic-link libraries by placing them alongside signed, legitimate executables.

Key Facts

Technique ID
T1574.002
Persistence
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1574.002.
  • Tactical Phase: Persistence.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: CISA Advisory AA21-189A
"The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload."
U.S. District Court for the Northern District of Texas View full case dossier →