Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismdefense-evasion-methodpersistence-methodcommand-and-control-method

Multi-stage loaders use DLL sideloading and signed binaries to hide final payloads

Updated 1mo agoFirst seen May 17, 20261 source

Researchers detailed two separate malware chains that rely on deeply layered staging, DLL sideloading, and trusted signed software to conceal execution. One campaign, dubbed Eimeria, starts from a RAR5 archive containing the signed dsclock.exe, a malicious zlibwapi.dll, and an encrypted payload that decrypts into an IExpress package and then an AutoIt-based RunPE loader. The chain restores ntdll.dll to evade EDR hooks, decrypts later stages with AES-128-CBC, RC4, and LZNT1, hollows explorer.exe, svchost.exe, or taskhostw.exe, and injects a small .NET RAT that beacons over WebSocket to 94.26.90.139:3006. It also sets persistence through a Run key and scheduled task and uses delays, sleep checks, and CPU and memory stress tests to frustrate analysis.

A second intrusion set tied to UAC-0184 / MB-0007 used Ukraine-themed lures and messenger delivery to target Ukrainian Defense Forces personnel, beginning with LNK files that called bitsadmin to fetch HTA content from 169.40.135.35 for execution via mshta. The downloaded archive abused legitimate Plane9 components for sideloading through Cluster-Overlay64.exe, Plane9Engine.dll, and openvr_api.dll, then decoded kernel-diag.lib into evr.dll and unpacked filter.bin by rebuilding IDAT chunks, XOR-decoding with key 0x227E9BDE, and decompressing with LZNT1. The final bundle included signed utilities such as Microsoft-signed VSLauncher.exe and a renamed PassMark Endpoint DLL, indicating the actor likely repurposed a signed network stack and dump-capable tooling for covert internal communications, with controller details possibly discovered dynamically over multicast 224.0.0.255:31339 and TCP 31339 rather than a fixed external C2.

Share:
Multi-stage loaders use DLL sideloading and signed binaries to hide final payloads
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
May 18, 20261mo ago

Synaptic Security publishes technical analysis of UAC-0184 loader chain

Synaptic Security published a technical breakdown of a UAC-0184 / MB-0007 malware chain that used HTA delivery, a ZIP archive, Plane9 DLL sideloading, pseudo-PNG payload reconstruction, and LZNT1 decompression. The report highlighted use of signed utilities including Microsoft-signed VSLauncher.exe and a PassMark Endpoint DLL, and assessed that controller information may be obtained dynamically rather than from a hardcoded external C2.

CERT-UA reports UAC-0184 campaign targeting Ukrainian defense personnel

CERT-UA reporting described campaigns attributed to UAC-0184 / MB-0007 that targeted Ukrainian Defense Forces personnel using Ukraine-themed social engineering and messenger-based delivery. The campaign used LNK lures that invoked bitsadmin to fetch HTA files and continue the infection chain.

May 17, 20261mo ago

Researchers analyze Eimeria multi-stage malware loader

Researchers documented a newly labeled malware loader called Eimeria that uses a five-layer chain beginning with a RAR5 archive and DLL side-loading to ultimately deploy a .NET RAT. The analysis detailed persistence via a Run key and scheduled task, anti-analysis checks, process hollowing, and WebSocket C2 communications to 94.26.90.139:3006.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Malware
2 linked
Affected products
3 linked
VirustotalWindowsNet
Organizations
8 linked
Trend MicroVirustotalCynetBkavIPinfoDedik Services LimitedDEDIK Services LtdDuality Software Co. Ltd.
SOURCE COVERAGE

Sources

1 reference tracked. Mallory keeps watching after this page renders.

1 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.