logo

Yet another DCOM object for lateral movement

ID: 80e2fcfc-a94a-5309-9504-0c661323bade

STIX ID: report--80e2fcfc-a94a-5309-9504-0c661323bade

Feed Name: Securelist by Kaspersky

Date Published: 2025-12-19

Date Updated: 2026-04-29

Author: Haidar Kabibo

...
...

The report introduces a new DCOM abuse technique that leverages the COpenControlPanel/IOpenControlPanel interface to load registered Control Panel DLLs through the COM Surrogate (dllhost.exe) for remote code execution and persistence. It reviews the reliability and detections of existing Impacket dcomexec objects across Windows versions, details practical enumeration methods (PowerShell, C++, OleViewDotNet), and provides detection guidance such as monitoring specific Control Panel registry paths, dllhost.exe hosting unusual COM objects, and Remote Registry usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.