RemoteInjector is a Windows loader used to execute next-stage payloads, notably Havoc beacons, during long-running intrusions attributed with high confidence to the Iranian state-linked threat actor Lemon Sandstorm, also tracked by some vendors as Pioneer Kitten, Fox Kitten, Rubidium, Parisite, and UNC757. It has been observed in espionage-focused operations against strategic critical infrastructure in the Middle East, where the actor used it as part of a broader toolkit that included web shells, credential theft utilities, proxying tools, and additional backdoors.
The malware’s primary role is staged payload execution. Operators deployed RemoteInjector through masqueraded scheduled tasks and invoked it with command-line parameters directing it to load a separate DLL payload, which then launched Havoc. Observed variants included binaries renamed to resemble legitimate Windows processes, reinforcing its role in stealthy execution and defense evasion. Reported deployments occurred in 2024 on multiple systems, with the loader repeatedly used to start additional Havoc payloads as the intrusion evolved.
RemoteInjector is associated with persistence through scheduled-task execution and with post-compromise operations rather than initial access. In the observed campaign, initial access relied on stolen VPN credentials, after which the actor used RemoteInjector to maintain footholds and expand access inside the victim environment. Its use alongside renamed binaries and DLL-based payload loading indicates an emphasis on blending into normal system activity while launching operator-controlled implants.
RemoteInjector targets Windows environments and functions as an enabling component in multi-stage intrusions focused on long-term access, espionage, and strategic prepositioning inside enterprise and critical infrastructure networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Scheduled task runs RemoteInjector malware ‘dllhost.exe’ with command line arguments “-f C:\Windows\apppatch\version.dll -ER --ls --path powershell.exe". This executes a Havoc payload. | Analysis of these executables identified that, in this case, the main executable (conhost.exe) is a loader used to execute a separate payload (conhost.dll). FortiGuard tracks this loader component as RemoteInjector.
1 distinct technique documented for this family, organized by ATT&CK tactic.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used to execute next-stage payloads (e.g., Havoc).
A loader used to execute Havoc backdoors via scheduled tasks.
A loader that accepts command-line switches, loads a specified DLL payload, and spawns it in a spoofed process context for execution.
RemoteInjector is a loader/injector used to launch Havoc payloads by proxy-loading malicious DLLs such as version.dll, conhost.dll, and a victim-named DLL. It was repeatedly deployed through scheduled tasks using masqueraded binaries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.