HomeSecurityHackers Exploit c-ares DLL Side-Loading

Hackers Exploit c-ares DLL Side-Loading

Security experts have revealed details of an active malware campaign that exploits a DLL side-loading in a legitimate binary linked to the open-source c-ares. This vulnerability allows attackers to bypass security checks and deliver a wide range of common trojans and stealers.

See also: Russian APT28 conducts credential theft campaign

DLL side-loading

“Attackers achieve evasion by combining a malicious libcares-2.dll with any signed version of the legitimate ahost.exe (which they often rename) to execute their code,” Trellix. “This DLL side-loading technique allows the malware to bypass traditional signature-based security defenses.”

The campaign has been observed distributing various types of malware, including Agent Tesla, CryptBot, Formbook, Lumma Stealer, Vidar Stealer, Remcos RAT, Quasar RAT, DCRat, and XWorm. Targets include employees in areas such as finance, procurement, supply chain, and administration, in sectors such as oil and gas, and import and export. The decoys are written in Arabic, Spanish, Portuguese, and English, indicating a regional focus for the attacks.

See also: Target: Dev server offline – Hackers say they stole source code

Hackers Exploit c-ares DLL Side-Loading

The attack relies on placing a malicious version of the DLL in the same directory as the vulnerable binary, exploiting search order hijacking to execute the malicious DLL instead of the legitimate one. The executable “ahost.exe” used in the campaign is signed by GitKraken and is usually part of the GitKraken Desktop application.

An analysis of the object on VirusTotal shows that it is distributed under various names, such as “RFQ_NO_04958_LG2049 pdf.exe,” “PO-069709-MQ02959-Order-S103509.exe,” and “Fatura da DHL.exe,” indicating the use of invoice and request for quotation (RFQ) themes to trick users into opening it.

The revelation coincides with Trellix reporting an increase in Facebook phishing scams that use the Browser-in-the-Browser (BitB) to simulate a Facebook authentication screen, tricking users into entering their credentials. This technique creates a fake pop-up window inside the victim’s legitimate browser window using an iframe, making it difficult to distinguish between a genuine and a fake login page.

See also: Hacker jailed for breaching Rotterdam and Antwerp ports

Hackers Exploit c-ares DLL Side-Loading

Evidence suggests that these phishing attacks may be continuing as early as July 2025.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS