A public malware-development tutorial and companion GitHub repository demonstrated a Windows persistence method that hijacks the Certificate Propagation Service (CertPropSvc) by changing the ServiceDll value under HKLM\SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters to an attacker-controlled DLL. Because the service loads that DLL when it starts or restarts, the technique can provide durable execution on compromised hosts while blending into a legitimate built-in Windows service; the material notes that administrative privileges are required to modify the HKLM registry path.
The published proof of concept included simple C/C++ examples and repository files such as meow.cpp, meow.dll, meow2.cpp, pers.c, and pers.exe. One payload writes a marker string to a file to confirm execution, while another uses WSAConnect to establish a reverse shell and launch cmd.exe, illustrating how the hijack can move from persistence to interactive command execution if defenders do not detect the altered service DLL path.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A tutorial post described a Windows persistence technique that hijacks the Certificate Propagation Service (CertPropSvc) by changing its ServiceDll registry value under HKLM\SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters to an attacker-controlled DLL. The demonstration showed payload execution when CertPropSvc is restarted, including a DLL that writes a marker file and a reverse-shell DLL.
The latest visible GitHub commit for the tutorial repository was "malware persistence 28: add readme." The repository snapshot dates that commit to September 17, 2025.
Repository files associated with the persistence tutorial, including meow.cpp, meow.dll, meow2.cpp, pers.c, and pers.exe, were committed under a label indicating "malware persistence 28." The repository snapshot dates these file-associated commits to September 16, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.