Potentially Suspicious Image Load of Tlscsp.dll

Rule Info

Name
Potentially Suspicious Image Load of Tlscsp.dll
Author
Jonathan Peters (Nextron Systems)
Description
Detects tlscsp.dll ("Microsoft Remote Desktop Services Cryptographic Utility") loaded by a process outside standard Microsoft or system directories. The DLL contains a hardcoded RC4 key exposed through its LsCsp_EncryptHwid export, providing a predictable cryptographic primitive that malware can leverage to decrypt payloads or encrypt data without embedding custom crypto code. Loading this DLL from an unexpected location is potentially suspicious, as threat actors abuse a trusted system component to perform cryptographic operations natively, bypassing detection that would otherwise flag unsigned or anomalous crypto implementations.
Date
2026-09-24 00:00:00
Modified
None
Id
ca30dc4c-bcaa-4cb1-a4ac-871f828e0b06
Tags
attack.stealth attack.t1027
Type
Nextron Sigma feed only (private)

Rule History