logo

BITS Persistence for Script Kiddies

ID: d752fac7-122f-511f-8273-4c866d8ef2f3

STIX ID: report--d752fac7-122f-511f-8273-4c866d8ef2f3

Feed Name: TrustedSec blog

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report details how attackers can abuse the Windows Background Intelligent Transfer Service (BITS) COM interface to download/upload files, execute commands, and establish persistent execution by using IBackgroundCopyJob2::SetNotifyCmdLine—including examples showing how to craft command lines that force non-zero exit codes so BITS will re-run the command after its retry delay. The write-up includes code snippets for connecting to BITS, creating jobs, adding files, resuming and completing jobs, and explains how jobs persist across reboots, enabling long-term persistence via a legitimate OS service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.