logo

Proxying Your Way to Code Execution – A Different Take on DLL Hijacking 

ID: d114df9b-71be-590d-a598-ee97c01823a8

STIX ID: report--d114df9b-71be-590d-a598-ee97c01823a8

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2024-09-26

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog describes a DLL proxying technique enabling low-privilege attackers to run malicious code inside trusted processes (Outlook, Teams, msedge, etc.) by abusing writable AppData DLLs or HKCU COM registry entries; it includes discovery methodology, proof-of-concepts, an automation tool (FaceDancer), weaponization details (delayed execution in DllMain and Cobalt Strike payloads), and notes that Microsoft acknowledged the findings but declined to patch them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.