logo

COM Objects Hijacking

ID: 11638bda-1401-5d80-8f4a-f1d635fdb0a4

STIX ID: report--11638bda-1401-5d80-8f4a-f1d635fdb0a4

Feed Name: VirusTotal Blog

Threat Score
70/100

Date Published: 2024-03-07

Date Updated: 2026-05-01

Author: Joseliyo Sánchez

...
...

This report analyzes how threat actors and malware families abuse Windows COM hijacking (MITRE T1546.015) for persistence and privilege escalation, enumerating commonly abused CLSIDs, sample behavior from families like Berbew and multiple RATs (Remcos, AsyncRAT, BitRAT, DarkMe), common payload locations, and providing IoCs plus Sigma/Livehunt detection rules to support detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.