Skip to content

Topic

DLL sideloading and signed-binary abuse

A technique abusing signed, legitimate executables to sideload malicious DLLs placed alongside them, bypassing security controls that trust signatures.

Current stories

security3 publishersConfirmed

Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption
Insufficient
Hype gap+18
Incentives40
Confidence60
security8 publishersConfirmed

Attackers stage a RAT lure on the real chatgpt.com using a Custom GPT

Huntress traced a RAT campaign that hides its first-stage lure in a ChatGPT Custom GPT on the real chatgpt.com, across at least 40 incidents. Because the page sits on a trusted domain, blocking the ClickFix PowerShell paste is the control that works.

Perspective Coverage

8 publishers
Builder
Builder 30%
Operator
Operator 64%
Investor
Investor 6%

Reality

Evidence70
Adoption20
Hype gap+30
Incentives40
Confidence68
security1 publisherOne report

Sophos ties Windows Terminal ClickFix lures to a tunneling campaign running since March

Sophos linked ClickFix lures that open Windows Terminal, not the Run dialog, to STAC4924, a campaign it has tracked since at least March. The intrusions plant Lorem Ipsum Loader and a Python reverse-tunnel implant that relays attacker traffic through the victim host.

Reality

Evidence62
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence58
security4 publishersConfirmed

Attackers move the ClickFix paste into Windows Terminal to land a multi-stage intrusion chain

Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.

Perspective Coverage

4 publishers
Builder
Builder 20%
Operator
Operator 75%
Investor
Investor 5%

Reality

Evidence65
Adoption
Insufficient
Hype gap+20
Incentives30
Confidence65
security4 publishersConfirmed

Silver Fox delivered ValleyRAT through signed adware that users whitelist themselves

Kaspersky traced one submitted installer to a modified Chinese wallpaper tool whose signed executable sideloads a malicious libcef.dll, and the same installer switches Windows Defender off before it ever runs.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 67%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence66
security3 publishersConfirmed

BambooToken moves its Windows and Linux command channel onto MQTT brokers

Black Lotus Labs counted about a dozen compromised enterprises, mostly in Asia and South America, on a framework that has been publishing operator commands to infected hosts through IoT message brokers since 2024.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 62%
Investor
Investor 11%

Reality

Evidence66
Adoption18
Hype gap+20
Incentives
Insufficient
Confidence64