Skip to content

Mavinject Process Injection

Attackers abuse the signed App-V utility mavinject.exe and its undocumented /INJECTRUNNING flag to inject an arbitrary DLL into a running process.

mavinject.exe is a signed Microsoft utility shipped with Application Virtualization (App-V) and, on modern Windows, present by default even where App-V is never used. Its documented job is to inject the App-V runtime DLL into a virtualized application's process. An undocumented command-line flag, /INJECTRUNNING, lets it inject any DLL into any running process by PID — turning a signed, trusted binary into a generic DLL injector that needs no custom loader code at all.

Because App-V is rarely deployed on ordinary endpoints, the mere presence of mavinject.exe executing is itself a strong anomaly, independent of what it is asked to inject.

How it works

The attacker needs only a target PID and a path to their DLL:

text
mavinject.exe 4092 /INJECTRUNNING C:\Users\Public\payload.dll

Internally, mavinject opens the target process, allocates a buffer for the DLL path, writes it, and creates a remote thread starting at LoadLibraryW — mechanically the same primitive as a hand-written CreateRemoteThread injector, except the process doing it is C:\Windows\System32\mavinject.exe, Microsoft-signed and rarely present in security-tool baselines as suspicious. Malware droppers use it as a one-line substitute for writing their own injection code, commonly to load a DLL into a legitimate host process such as explorer.exe or a browser.

Detection & analysis

Static analysis:

  • A dropped or referenced mavinject.exe on a system where App-V is not installed/licensed is itself worth flagging — check for the App-V client (AppVClient.exe) and related services; its absence alongside mavinject usage is a strong tell.

Dynamic analysis:

  • Command-line telemetry is the most reliable signal: mavinject.exe combined with /INJECTRUNNING and a numeric PID is not a pattern that appears in legitimate App-V virtualization (which invokes it differently, without that flag, from the App-V client itself).
  • Correlate the target PID with a subsequent unexpected module load in that process (Sysmon Event ID 7, ImageLoad) — a DLL from a user-writable path loading into a long-running, unrelated process like explorer.exe.

Detection rule hint:

Alert on Sysmon Event ID 1 where Image ends with \mavinject.exe AND the command line contains /INJECTRUNNING. Treat any hit as high severity by default — the flag's use outside App-V's own internal invocation pattern is close to unconditionally malicious.

Votes

Comments(0)