Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
атакующему заранее понадобится получить локальный доступ, узнать учетные данные обычного пользователя, а также имя учетной записи, которая может принадлежать администратору
Dormann showed that a non-admin could, for example, change the .txt file association in the admin’s hive to launch calc.exe instead of a text editor
successful exploitation would allow non-admin users to modify the classes registry hive and gain automatic code execution when the admin account logs into a compromised system.
A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution.
атакующему заранее понадобится получить локальный доступ, узнать учетные данные обычного пользователя, а также имя учетной записи, которая может принадлежать администратору
The researcher claims the original exploit did not require additional user credentials and could coerce ProfSvc (and even achieve kernel-level impersonation as NT AUTHORITY\SYSTEM) to load any hive
successful exploitation would allow non-admin users to modify the classes registry hive and gain automatic code execution when the admin account logs into a compromised system.
an attacker can overwrite COM objects or shell extensions that load automatically when the administrator logs in, turning the hijacked hive into a persistence and code-execution mechanism that runs with admin privileges during a normal sign-in.
атакующему заранее понадобится получить локальный доступ, узнать учетные данные обычного пользователя, а также имя учетной записи, которая может принадлежать администратору
The researcher claims the original exploit did not require additional user credentials and could coerce ProfSvc (and even achieve kernel-level impersonation as NT AUTHORITY\SYSTEM) to load any hive
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.