Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections.
Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Similar to Regsvr32 / ”Squiblydoo”, CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other application control defenses since CMSTP.exe is a legitimate binary that may be signed by Microsoft.
CMSTP.exe can also be abused to Bypass User Account Control and execute arbitrary commands from a malicious INF through an auto-elevated COM interface.
Rules on DetectionCode tagged with T1218.003.
| Rule | Level | Log source |
|---|---|---|
| Bypass UAC via CMSTP | high | windows / process_creation |
| CMSTP App Paths Registry Key Modification | high | windows / registry_event |
| CMSTP Execution Process Access | high | windows / process_access |
| CMSTP Execution Process Creation | high | windows / process_creation |
| CMSTP UAC Bypass via COM Object Access | high | windows / process_creation |
| DLL Loaded From Suspicious Location Via Cmspt.EXE | high | windows / image_load |
| Outbound Network Connection Initiated By Cmstp.EXE | high | windows / network_connection |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| CMLUA Or CMSTPLUA UAC Bypass | TTP | NULL | Sysmon EventID 7 |
| UAC Bypass With Colorui COM Object | TTP | NULL | Sysmon EventID 7 |
| Wbemprox COM Object Execution | TTP | NULL | Sysmon EventID 7 |
| Windows Unusual Process Load Mozilla NSS-Mozglue Module | Anomaly | NULL | Sysmon EventID 7 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupCobalt Group | Cobalt Group has used the command |
| GroupMuddyWater | MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload. |
| Used by | Procedure example |
|---|---|
| MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile. |
| MalwareLockBit 3.0 | LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.