logo

DCOM Again: Installing Trouble

ID: d98d5c3d-fe78-5ad1-9937-66adb834c73d

STIX ID: report--d98d5c3d-fe78-5ad1-9937-66adb834c73d

Feed Name: SpecterOps Blog

Date Published: 2025-09-29

Date Updated: 2026-04-30

Author: Craig Wright

...
...

The report presents a DCOM lateral movement technique leveraging the Windows Installer Custom Action server to trigger execution of attacker-controlled DLLs by abusing ODBC driver installation and configuration (SQLInstallDriverEx and SQLConfigDriver), with execution occurring under msiexec in the target user context. It includes reverse engineering insights into MSI/COM interfaces, a released Beacon Object File to operationalize the method locally or remotely with valid credentials, and defensive guidance to monitor ODBC-related registry changes that indicate driver installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.