216.73.216.6

Finding Minhook in a sideloading attack – and Sweden too

· Published 01/05/2025 14:50 · Modified 01/05/2025 20:27

Export JSON

Essential information

Published
01/05/2025 14:50
Modified
01/05/2025 20:27
Tags
2025-05-01 api hooking cobalt strike digital signature dll sideloading minhook
Related entities
10 techniques (mitre), 1 malware, 3 others

Description

A threat actor campaign targeting multiple locations was observed in late 2023 and early 2024. Initially focused on the Far East, it later shifted to Sweden. The attacks used techniques, employing the library to detour Windows API calls. The clean loader was obtained from infected systems rather than being part of the sideloading package. Components were signed with a compromised . The final payload was . Three sideloading scenarios were identified: MiracastView, PrintDialog, and SystemSettings. The Swedish connection revealed an installer with components from previous scenarios and the use of an expired from a Korean game developer.

External references