Hijack Execution Flow

T1574

Technique with 12 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

There are many ways an adversary may hijack the flow of execution, including by manipulating how the operating system locates programs to be executed. How the operating system locates libraries to be used by a program can also be intercepted. Locations where the operating system looks for programs/resources, such as file directories and in the case of Windows the Registry, could also be poisoned to include malicious payloads.

Detection rules142

Rules on DetectionCode tagged with T1574 or one of its sub-techniques.

Sigma106

RuleLevelLog sourceTechnique
HackTool - SharpUp PrivEsc Tool Executioncriticalwindows / process_creationT1574.005
Abuse of Service Permissions to Hide Services Via Set-Servicehighwindows / process_creationT1574.011
Abuse of Service Permissions to Hide Services Via Set-Service - PShighwindows / ps_scriptT1574.011
Aruba Network Service Potential DLL Sideloadinghighwindows / image_loadT1574.001
Code Injection by ld.so Preloadhighlinux / NULLT1574.006
DHCP Callout DLL Installationhighwindows / registry_setT1574.001
DHCP Server Error Failed Loading the CallOut DLLhighwindows / NULLT1574.001
DHCP Server Loaded the CallOut DLLhighwindows / NULLT1574.001
DLL Search Order Hijackig Via Additional Space in Pathhighwindows / file_eventT1574.001
DLL Sideloading by VMware Xfer Utilityhighwindows / process_creationT1574.001
DLL Sideloading Of ShellChromeAPI.DLLhighwindows / image_loadT1574.001
DNS Server Error Failed Loading the ServerLevelPluginDLLhighwindows / NULLT1574.001
Fax Service DLL Search Order Hijackhighwindows / image_loadT1574.001
HackTool - Powerup Write Hijack DLLhighwindows / file_eventT1574.001
Malicious DLL File Dropped in the Teams or OneDrive Folderhighwindows / file_eventT1574.001

Splunk36

RuleTypeRiskData sourceTechnique
Detect Path Interception By Creation Of program exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1574.009
GitHub Workflow File Creation or ModificationHuntingNULLSysmon for Linux EventID 11, Sysmon EventID 11T1574.006
Linux Auditd Preload Hijack Library CallsTTPNULLLinux Auditd ExecveT1574.006
Linux Auditd Preload Hijack Via Preload FileTTPNULLLinux Auditd Path, Linux Auditd CwdT1574.006
Linux Possible Privilege Escalation via PYTHONPATHTTPNULLSysmon for Linux EventID 11T1574.007
Linux Preload Hijack Library CallsTTPNULLSysmon for Linux EventID 1T1574.006
MSI Module Loaded by Non-System BinaryHuntingNULLSysmon EventID 7T1574.001
Msmpeng Application DLL Side LoadingTTPNULLSysmon EventID 11T1574.001
Python PYTHONPATH Modification During Package InstallationTTPNULLSysmon EventID 1 AND Sysmon EventID 13T1574.007
Reg exe Manipulating Windows Services Registry KeysTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1574.011
Shai-Hulud Workflow File Creation or ModificationTTPNULLSysmon for Linux EventID 11, Sysmon EventID 11T1574.006
Windows BitDefender Submission Wizard DLL SideloadingTTPNULLSysmon EventID 7T1574
Windows DLL Search Order Hijacking HuntHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Windows Event Log Security 4688T1574.001
Windows DLL Search Order Hijacking Hunt with SysmonHuntingNULLSysmon EventID 7T1574.001
Windows DLL Search Order Hijacking with iscsicplTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1574.001

Sub-techniques12

IDNameExamples
T1574.001DLL114
T1574.004Dylib Hijacking1
T1574.005Executable Installer File Permissions Weakness1
T1574.006Dynamic Linker Hijacking10
T1574.007Path Interception by PATH Environment Variable4
T1574.008Path Interception by Search Order Hijacking2
T1574.009Path Interception by Unquoted Path2
T1574.010Services File Permissions Weakness1
T1574.011Services Registry Permissions Weakness1
T1574.012COR_PROFILER2
T1574.013KernelCallbackTable2
T1574.014AppDomainManager1

Groups0

None recorded.

Software9

Campaigns2

Procedure examples11

Software9

Used byProcedure example
MalwareCOATHANGER

COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`.

MalwareDarkGate

DarkGate edits the Registry key HKCU\Software\Classes\mscfile\shell\open\command to execute a malicious AutoIt script. When eventvwr.exe is executed, this will call the Microsoft Management Console (mmc.exe), which in turn references the modified Registry key.

MalwareDenis

Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe.

MalwareDtrack

One of Dtrack can replace the normal flow of a program execution with malicious code.

MalwareNightdoor

Nightdoor uses a legitimate executable to load a malicious DLL file for installation.

MalwareRaspberry Robin

Raspberry Robin will drop a copy of itself to a subfolder in %Program Data% or %Program Data%\\Microsoft\\ to attempt privilege elevation and defense evasion if not running in Session 0.

MalwareSaint Bot

Saint Bot will use the malicious file slideshow.mp4 if present to load the core API provided by ntdll.dll to avoid any hooks placed on calls to the original ntdll.dll file by endpoint detection and response or antimalware software.

MalwareShimRat

ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls.

View all 9 software examples

Campaigns2

Used byProcedure example
CampaignC0017

During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries.

CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.