logo

New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment

ID: 74e3fd20-33c6-5148-8d35-15c3f15f0af6

STIX ID: report--74e3fd20-33c6-5148-8d35-15c3f15f0af6

Feed Name: Crowdstrike Blog

Date Published: 2026-06-18

Date Updated: 2026-07-23

Author: Mathilde Venault

...
...

This report analyzes the internals of ClickOnce deployments, explaining how rundll32.exe calls dfshim.dll which locates and loads dfdll.dll (via GetRequestedRuntimeInfo), how dfdll!ActivateDeploymentW invokes InvokeServer/BindToServer to initialize the COM server (using CoCreateInstance with a specific CLSID) and may launch dfsvc.exe, and why dfshim.dll acts as an intermediate between System32 and .NET runtime libraries; the focus is on normal deployment mechanics rather than malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.