Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Threat Actors
/
Attor
Threat Actor
Unknown origin
Attor
Adversary group targeting diplomatic missions and governmental organisations.
MITRE ATT&CK TTPs
1
T1021.003
Distributed Component Object Model
Lateral Movement
Source Articles
Introduction to COM usage by Windows threats
Component Object Model (COM) is a foundational Windows technology increasingly exploited by threat actors for malicious purposes such as persistence, lateral movement, execution, and evasion. Malware families like Qakbot, Gh0stRAT, and WarmCookie leverage COM interfaces to interact with Windows services including Task Scheduler, WMI, and BITS, often bypassing traditional detection mechanisms. These threats use indirect vtable calls and DCOM for stealthy operations, making static analysis more complex. Understanding COM usage is critical for effective threat hunting and reverse engineering.
talos
·
1mo ago