[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-GejuXexRCLfoObOj2_85ab3PI14nnkV5gCikszTbE0":3},{"article":4,"iocs":47,"watch_terms":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":31},"4e8e264f-96c2-400a-921f-4d66ad49eccb","Related archive contains legit signed WinWord.exe from Microsoft to load a malicious \"AppvIsvSubs...","related-archive-contains-legit-signed-winword-exe-from-microsoft-to-load-a-malic","Related archive contains legit signed WinWord.exe from Microsoft to load a malicious \"AppvIsvSubsystems64.dll\" file...\n🤷‍♂️ https:\u002F\u002Ft.co\u002Fcy4v9TE3hz","A malware campaign is leveraging legitimate, Microsoft-signed WinWord.exe executables to sideload a malicious AppvIsvSubsystems64.dll file. This DLL hijacking technique abuses the trust placed in Microsoft-signed binaries to evade detection and execute arbitrary code. The attack demonstrates a sophisticated supply-chain-adjacent technique that exploits DLL search order and code signing trust.","Legitimate signed WinWord.exe used to load malicious AppvIsvSubsystems64.dll",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2041798940291428419","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHFXsuEcXsAA1xza.jpg","2026-04-08T08:42:56+00:00","2026-04-08T09:00:18.24749+00:00",8,[18,21,24],{"name":19,"type":20},"WinWord.exe","product",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":26},"DLL sideloading","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":27,"icon":11,"name":29,"slug":30},"Malware","malware",[32,37,42],{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":43},{"id":44,"icon":11,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48],{"type":30,"value":49,"context":50},"AppvIsvSubsystems64.dll","Malicious DLL sideloaded via legitimate WinWord.exe",[22,19]]