logo

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

ID: ef395941-af72-5b23-afb6-8001f5535003

STIX ID: report--ef395941-af72-5b23-afb6-8001f5535003

Feed Name: Crowdstrike Blog

Threat Score
65/100

Date Published: 2026-06-18

Date Updated: 2026-08-06

Author: Mathilde Venault

...
...

**Executive Summary:** This report analyzes how threat actors can weaponize Microsoft ClickOnce deployment mechanisms—highlighting ease of delivery, lack of user awareness, no-elevation installation, built-in update/persistence via .appref-ms, execution under legitimate processes for stealth, prior research techniques (dependency hijacking and .appref-ms abuse), and a newly identified COM hijacking attack surface—then outlines detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.