Description

A sophisticated DLL sideloading attack abuses Microsoft OneDrive by placing a weaponized version.dll alongside OneDrive.exe, causing the legitimate application to load the malicious library first and execute attacker code under a trusted Microsoft process. Because many Windows programs use version.dll to retrieve file version information, attackers target that library specifically and exploit Windows’ DLL search order so the malicious DLL is loaded from the application directory before the real System32 copy. This lets the attacker run code in the security context of a digitally signed OneDrive binary, which helps the malware evade behavioral and signature-based defenses. To remain stealthy and stable, the malicious version.dll both proxies legitimate functions and executes malicious logic: it exports the same APIs, forwards calls to the real System32 version.dll, and in parallel spawns threads that run payloads without blocking OneDrive’s initialization. The attack uses advanced hooking via Vectored Exception Handling and PAGE_GUARD to intercept API calls (for example CreateWindowExW) by deliberately triggering single-step exceptions and handling them in a way that redirects execution flow to attacker-controlled routines. The hook re-arms itself after each interception, avoiding persistent inline patches that many security tools detect, and the DLL launches additional hidden processes to carry out covert operations. Because the technique runs code inside a trusted, digitally signed executable, defenders must focus on prevention and detection at the supply and runtime layers. Recommended mitigations include strict application whitelisting, validating digital signatures of loaded libraries, monitoring DLL load paths and unexpected local DLLs next to signed binaries, restricting write access to application directories, and using endpoint controls to detect unusual vectored-exception hooking behavior. These steps reduce the risk that a malicious version.dll placed near OneDrive.exe can achieve persistent, stealthy arbitrary code execution.