Skip to content

Malware

SADBRIDGE

According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various injection techniques to execute malicious payloads.

SADBRIDGE is a Windows malware family.

Background

Elastic describes SADBRIDGE as a loader distributed inside an MSI executable that combines DLL side-loading with a range of injection methods to run its malicious payloads. It misuses trusted programs such as x64dbg.exe and MonitoringHost.exe to side-load rogue DLLs like x64bridge.dll and HealthServiceRuntime.dll, which in turn launch later stages and shellcode.


Source: Malpedia (Fraunhofer FKIE).