logo

Forget PSEXEC: DCOM Upload & Execute Backdoor

ID: 9b5d5259-35ce-5513-b093-d30c7afc8696

STIX ID: report--9b5d5259-35ce-5513-b093-d30c7afc8696

Feed Name: Deep Instinct Blog

Threat Score
75/100

Date Published: 2024-11-25

Date Updated: 2026-04-27

Author: Eliran Nissan

...
...

This report documents a newly discovered DCOM lateral movement technique that leverages undocumented IMsiServer/IMsiCustomAction interfaces to remotely upload a strong‑named .NET assembly into the Global Assembly Cache (GAC) on a target, load it into an MSIEXEC service process, and invoke exported functions to achieve remote code execution and a backdoor-like persistence. The author details reversing steps, a full proof‑of‑concept implementation, limitations (domain membership, DCOM hardening parity, strong‑name requirement), and detection indicators such as MSIEXEC child processes, GAC writes/loads, and relevant event logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.