Mavinject Process Injection
Attackers abuse the signed App-V utility mavinject.exe and its undocumented /INJECTRUNNING flag to inject an arbitrary DLL into a running process.
mavinject.exe is a signed Microsoft utility shipped with Application
Virtualization (App-V) and, on modern Windows, present by default even where
App-V is never used. Its documented job is to inject the App-V runtime DLL
into a virtualized application's process. An undocumented command-line flag,
/INJECTRUNNING, lets it inject any DLL into any running process by
PID — turning a signed, trusted binary into a generic DLL injector that needs
no custom loader code at all.
Because App-V is rarely deployed on ordinary endpoints, the mere presence of
mavinject.exe executing is itself a strong anomaly, independent of what it
is asked to inject.
How it works
The attacker needs only a target PID and a path to their DLL:
mavinject.exe 4092 /INJECTRUNNING C:\Users\Public\payload.dllInternally, mavinject opens the target process, allocates a buffer for the
DLL path, writes it, and creates a remote thread starting at LoadLibraryW —
mechanically the same primitive as a hand-written CreateRemoteThread
injector, except the process doing it is C:\Windows\System32\mavinject.exe,
Microsoft-signed and rarely present in security-tool baselines as suspicious.
Malware droppers use it as a one-line substitute for writing their own
injection code, commonly to load a DLL into a legitimate host process such as
explorer.exe or a browser.
Detection & analysis
Static analysis:
- A dropped or referenced
mavinject.exeon a system where App-V is not installed/licensed is itself worth flagging — check for the App-V client (AppVClient.exe) and related services; its absence alongsidemavinjectusage is a strong tell.
Dynamic analysis:
- Command-line telemetry is the most reliable signal:
mavinject.execombined with/INJECTRUNNINGand a numeric PID is not a pattern that appears in legitimate App-V virtualization (which invokes it differently, without that flag, from the App-V client itself). - Correlate the target PID with a subsequent unexpected module load in that
process (Sysmon Event ID 7, ImageLoad) — a DLL from a user-writable path
loading into a long-running, unrelated process like
explorer.exe.
Detection rule hint:
Alert on Sysmon Event ID 1 where Image ends with \mavinject.exe AND the
command line contains /INJECTRUNNING. Treat any hit as high severity by
default — the flag's use outside App-V's own internal invocation pattern is
close to unconditionally malicious.