Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries.

Tactics
TA0003 TA0004 TA0005

Sub-technique of
T1574


See: MITRE ATT&CK