COM Objects Hijacking
ID: 11638bda-1401-5d80-8f4a-f1d635fdb0a4
STIX ID: report--11638bda-1401-5d80-8f4a-f1d635fdb0a4
Feed Name: VirusTotal Blog
Threat Score
This report analyzes how threat actors and malware families abuse Windows COM hijacking (MITRE T1546.015) for persistence and privilege escalation, enumerating commonly abused CLSIDs, sample behavior from families like Berbew and multiple RATs (Remcos, AsyncRAT, BitRAT, DarkMe), common payload locations, and providing IoCs plus Sigma/Livehunt detection rules to support detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
