BITS Persistence for Script Kiddies
ID: d752fac7-122f-511f-8273-4c866d8ef2f3
STIX ID: report--d752fac7-122f-511f-8273-4c866d8ef2f3
Feed Name: TrustedSec blog
This report details how attackers can abuse the Windows Background Intelligent Transfer Service (BITS) COM interface to download/upload files, execute commands, and establish persistent execution by using IBackgroundCopyJob2::SetNotifyCmdLine—including examples showing how to craft command lines that force non-zero exit codes so BITS will re-run the command after its retry delay. The write-up includes code snippets for connecting to BITS, creating jobs, adding files, resuming and completing jobs, and explains how jobs persist across reboots, enabling long-term persistence via a legitimate OS service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
