Elastic Security Labs’ analysis of roughly 100,000 Windows malware samples found defense evasion to be the most common ATT&CK tactic, followed by privilege escalation, execution, and persistence. Frequently observed behaviors included Windows Defender tampering, process injection, DLL side-loading, parent-PID spoofing, abuse of Rundll32 and Regsvr32, malicious MSI installers, and NTDLL unhooking.
Commodity malware increasingly used UAC-bypass techniques—including methods that abuse Windows’ trust in protected directories—alongside TrustedInstaller impersonation, elevated parent-process spoofing, and bring-your-own-vulnerable-driver activity. Security teams should prioritize behavioral detections for these elevation and evasion patterns, as well as monitoring for script hosts, WMI, scheduled tasks, Run keys, services, and credential-store access that commonly accompany malware execution and persistence.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs analyzed more than 100,000 Windows malware samples and found defense evasion to be the most prevalent observed tactic. The analysis identified trusted-directory-mimicking UAC bypasses, often associated with DLL side-loading, as the leading UAC-bypass method in its dataset.
Tenable published technical research describing a User Account Control bypass technique based on mocking trusted directories.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.