Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1546.015 Component Object Model Hijacking |
MalwareBBSRAT | BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList |
| T1546.015 Component Object Model Hijacking |
MalwareSVCReady | SVCReady has created the `HKEY_CURRENT_USER\Software\Classes\CLSID\{E6D34FFC-AD32-4d6a-934C-D387FA873A19}` Registry key for persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareFerocious | Ferocious can use COM hijacking to establish persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareKONNI | KONNI has modified ComSysApp service to load the malicious DLL payload. |
| T1546.015 Component Object Model Hijacking |
MalwareJHUHUGIT | JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}). |
| T1546.015 Component Object Model Hijacking |
MalwareMosquito | Mosquito uses COM hijacking as a method of persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareComRAT | ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location |
| T1546.015 Component Object Model Hijacking |
MalwareADVSTORESHELL | Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object. |
| T1546.015 Component Object Model Hijacking |
MalwareWarzoneRAT | WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter. |
| T1546.015 Component Object Model Hijacking |
ToolSILENTTRINITY | SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`. |
| T1546.015 Component Object Model Hijacking |
ToolPcShare | PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.