logo

Revisiting COM Hijacking

ID: d7d69969-ada1-58b0-bd1e-4e2e747bf754

STIX ID: report--d7d69969-ada1-58b0-bd1e-4e2e747bf754

Feed Name: SpecterOps Blog

Date Published: 2025-05-28

Date Updated: 2026-04-30

Author: Antero Guy

...
...

This post outlines a red-team technique leveraging Windows COM hijacking to establish stealthy persistence and achieve controlled code execution within commonly used applications, especially Chromium-based browsers (Edge/Chrome). It covers discovering viable CLSIDs via Procmon, creating a proxy DLL to maintain application stability while triggering a payload, and adding process checks to limit execution to target browsers for better stealth and potential access to browser data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.