Sub-technique of T1559 Inter-Process Communication.View on attack.mitre.org
Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE). Remote COM execution is facilitated by Remote Services such as Distributed Component Object Model (DCOM).
Various COM interfaces are exposed that can be abused to invoke arbitrary execution via a variety of programming languages such as C, C++, Java, and Visual Basic. Specific COM objects also exist to directly perform functions beyond code execution, such as creating a Scheduled Task/Job, fileless download/execution, and other adversary behaviors related to privilege escalation and persistence.
Rules on DetectionCode tagged with T1559.001.
| Rule | Level | Log source |
|---|---|---|
| CMSTP Execution Process Access | high | windows / process_access |
| DNS Query Request By Regsvr32.EXE | medium | windows / dns_query |
| Network Connection Initiated By Regsvr32.EXE | medium | windows / network_connection |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Process Writing DynamicWrapperX | Hunting | NULL | Sysmon EventID 11 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupGamaredon Group | Gamaredon Group malware can insert malicious macros into documents using a |
| GroupKimsuky | Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment. |
| GroupMedusa Group | Medusa Group has leveraged Component Object Model (COM) to bypass UAC. |
| GroupMuddyWater | MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook. |
| Used by | Procedure example |
|---|---|
| MalwareBumblebee | Bumblebee can use a COM object to execute queries to gather system information. |
| MalwareCLAIMLOADER | CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface. |
| MalwareDarkTortilla | DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder. |
| MalwareFunnyDream | FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms. |
| MalwareGelsemium | Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process. |
| MalwareHermeticWizard | HermeticWizard can execute files on remote machines using DCOM. |
| MalwareInvisiMole | InvisiMole can use the |
| MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.