Proxying Your Way to Code Execution – A Different Take on DLL Hijacking
ID: d114df9b-71be-590d-a598-ee97c01823a8
STIX ID: report--d114df9b-71be-590d-a598-ee97c01823a8
Feed Name: Black Hills Infosec Blog
Threat Score
This blog describes a DLL proxying technique enabling low-privilege attackers to run malicious code inside trusted processes (Outlook, Teams, msedge, etc.) by abusing writable AppData DLLs or HKCU COM registry entries; it includes discovery methodology, proof-of-concepts, an automation tool (FaceDancer), weaponization details (delayed execution in DllMain and Cobalt Strike payloads), and notes that Microsoft acknowledged the findings but declined to patch them.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
