logo

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

ID: 41e21d2a-5885-520c-95db-4efe26948d14

STIX ID: report--41e21d2a-5885-520c-95db-4efe26948d14

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
65/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Serhii Melnyk and Timmy Lister

...
...

This report analyzes LegacyHive, a public Windows proof-of-concept that persistently hijacks user profile registry hives by creating NT Object Manager directories and symbolic links, modifying ntuser.dat/UsrClass.dat offline, and using oplocks plus CreateProcessWithLogonW to force profile loading; the authors reproduced the chain on fully patched July 2026 systems, detail seven stages of exploitation, and provide detection guidance (YARA and hunting queries) and indicators for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.