New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
ID: ef395941-af72-5b23-afb6-8001f5535003
STIX ID: report--ef395941-af72-5b23-afb6-8001f5535003
Feed Name: Crowdstrike Blog
Threat Score
**Executive Summary:** This report analyzes how threat actors can weaponize Microsoft ClickOnce deployment mechanisms—highlighting ease of delivery, lack of user awareness, no-elevation installation, built-in update/persistence via .appref-ms, execution under legitimate processes for stealth, prior research techniques (dependency hijacking and .appref-ms abuse), and a newly identified COM hijacking attack surface—then outlines detection and mitigation strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
