logo

Hiding in Plain Sight with App Domain Manager Injection

ID: 8e071cb4-699b-54ce-923b-6888c3c0f751

STIX ID: report--8e071cb4-699b-54ce-923b-6888c3c0f751

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-02-19

Date Updated: 2026-04-28

...
...

**App Domain Manager injection** is a .NET framework feature abuse that lets attackers direct the runtime to load attacker-controlled assemblies via .exe.config files, remote HTTP/UNC paths, or environment variables (APPDOMAIN_MANAGER_ASM / APPDOMAIN_MANAGER_TYPE). The technique executes code inside legitimate, often Microsoft-signed processes (affecting any .NET Framework application), can enable local or remote execution and lateral movement, has been observed in red-team reporting, and requires defenders to rely on behavioral telemetry (assembly resolution logs, Process Monitor, Fusion logging) and monitoring of configuration/environment changes for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.