Potential McUtil.DLL Sideloading

Rule Info

Name
Potential McUtil.DLL Sideloading
Author
MalGamy (Nextron Systems)
Description
Detects potential DLL sideloading of "mcutil.dll", a technique where attackers place a malicious DLL alongside a legitimate vulnerable application to evade detection, gain persistence, and execute malicious code
Date
2025-02-26 00:00:00
Modified
None
Id
d3e86316-8bc7-4120-a115-4ed1d0570258
Tags
attack.defense-evasion attack.privilege-escalation attack.t1574.001 attack.t1574.002
Type
Nextron Sigma feed only (private)

Rule History