logo

LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One

ID: a8ff7eae-633d-51b5-835d-bd47e2f4b019

STIX ID: report--a8ff7eae-633d-51b5-835d-bd47e2f4b019

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-08-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

LockBit ransomware campaigns are increasingly using DLL sideloading to load malicious libraries through legitimate, signed applications (notably jarsigner.exe/jli.dll and MpCmdRun.exe/mpclient.dll), achieve persistence after initial access via remote management tools like MeshAgent and TeamViewer, and encrypt files with a hybrid RSA/AES scheme appending the .xlockxlock extension, enabling sophisticated evasion of reputation- and signature-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.