A proof-of-concept showed that Internet Explorer on Windows attempts to load a missing DLL named suspend.dll, creating an opportunity for DLL hijacking persistence. Using Process Monitor (Procmon) to trace iexplore.exe, the researcher observed the failed DLL lookup, then built a replacement C++ DLL that executed code when the browser launched while allowing Internet Explorer to continue running normally. The demonstration reportedly also worked on Windows 11 x64.
The technique relies on placing a malicious suspend.dll in Internet Explorer's load path so it is loaded automatically each time the browser starts, giving attackers a simple persistence mechanism. Microsoft describes Process Monitor as a Sysinternals utility for real-time visibility into file system, Registry, and process activity, and the tool's filtering and event-capture capabilities were central to identifying the missing dependency and validating the hijack path for defender awareness and malware hunting.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A proof-of-concept post demonstrated a persistence technique against Internet Explorer by identifying that iexplore.exe attempts to load a missing suspend.dll and replacing it with a malicious DLL. The renamed DLL executed when Internet Explorer launched while the browser continued to function normally, and the author reported the technique also worked on Windows 11 x64.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.