SparroWocky Trident Loader DLL Side-Loading (winfsp-x64.dll/DukeQt.dll)
Detects DLL side-loading of 'winfsp-x64.dll' or 'DukeQt.dll' by legitimate signed executables from non-standard directories. This behavior is associated with the FamousSparrow threat actor's 'SparroWocky' trident loader scheme, which leverages side-loading to execute malicious payloads in the context of trusted processes.
YARA-L

