Kaspersky has developed and deployed a machine-learning model specifically designed to detect DLL hijacking attacks within its Unified Monitoring and Analysis Platform SIEM system. DLL hijacking is a technique where attackers substitute a legitimate dynamic-link library (DLL) with a malicious one, allowing them to execute code within the trusted context of legitimate processes. This method is increasingly used by both mass malware operators and advanced persistent threat (APT) groups, making detection a significant challenge for traditional security solutions. The Kaspersky AI Technology Research Center led the development of this model, focusing on distinguishing between legitimate and malicious DLL loads by analyzing features such as file paths, process names, and file hashes. The model leverages both local system attributes and the global Kaspersky Security Network (KSN) cloud to enhance detection accuracy and reduce false positives. It can operate in two modes within the SIEM: on a correlator, where it analyzes events that have already triggered rules, and on a collector, where it processes all relevant events, albeit with higher resource consumption. The integration of this model into Kaspersky SIEM has already resulted in the detection of real-world DLL hijacking incidents, demonstrating its practical effectiveness. The model addresses the core challenge that malicious DLLs, when loaded by trusted processes, often evade traditional endpoint protection due to their appearance of legitimacy. Kaspersky's approach balances the need for robust detection with system performance, avoiding excessive scrutiny of trusted processes that could degrade user experience. The model's deployment is a response to the observed rise in DLL hijacking attacks globally, including targeted campaigns in regions such as Russia, Africa, and South Korea. Notably, malware families like Lumma and threat actors exploiting popular applications such as DeepSeek have utilized DLL hijacking for distribution. The machine-learning model was trained using a carefully selected set of features indicative of malicious activity, ensuring high detection rates while minimizing false alarms. Kaspersky's long-standing experience with AI in threat detection underpins the reliability of this new capability. The company has publicly detailed both the technical challenges of detecting DLL hijacking and the specific ways their model overcomes these obstacles. This innovation represents a significant advancement in the fight against sophisticated attack techniques that exploit the trust model of Windows systems. Organizations using Kaspersky SIEM now benefit from enhanced visibility and automated detection of DLL hijacking attempts, improving their overall security posture against evolving threats.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky publicly described integrating a machine-learning model for DLL hijacking detection into its Unified Monitoring and Analysis Platform, combining local process and library attributes with Kaspersky Security Network cloud validation. The company said the model can run on either a SIEM correlator or collector and produces confidence-ranked verdicts to improve detection accuracy and reduce false positives.
During pilot deployment in Kaspersky's Managed Detection and Response service, the machine-learning model detected several real-world DLL sideloading incidents, including APT activity, infostealer delivery, and a USB-based backdoor attack. These detections were presented as validation of the model's practical effectiveness.
Kaspersky's pilot testing also uncovered an infostealer DLL named policymanager.dll being loaded by a suspiciously located SettingSyncHost.exe, indicating DLL hijacking or sideloading behavior. The article does not provide a more specific date for this incident.
In another incident identified during pilot testing, a USB-borne attack used a legitimate Avast executable, CEFHelper.exe, to sideload a malicious wsc.dll loader. The loader decrypted and executed an encrypted backdoor on the victim system.
In one real-world incident later detected during Kaspersky MDR pilot testing, attackers exploited Microsoft SharePoint via CVE-2021-27076, established persistence with a scheduled task, and used a Cobalt Strike DLL disguised as SystemSettings.dll. Kaspersky attributed this activity with high confidence to the ToddyCat APT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcesecurelist.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.