A malware-development writeup detailed how attackers can use the Windows Terminal Services API function WTSEnumerateProcessesA to enumerate running processes and identify a target process ID by name, offering an alternative to more commonly monitored APIs such as CreateToolhelp32Snapshot, Process32First, and Process32Next. The technique relies on iterating through WTS_PROCESS_INFOA entries returned by the API and can require appropriate permissions, including query rights and in some cases privileges such as SeTcbPrivilege.
The same writeup showed how the process-discovery method can be chained into DLL injection, with a target process opened, remote memory allocated, a DLL path written into that memory, and a remote thread created to call LoadLibraryA. The article linked the approach to the Iranian espionage group CopyKittens—tracked by MITRE ATT&CK as G0052—highlighting how the API choice may help malware blend in by avoiding security detections tuned to more familiar process-enumeration methods.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A blog post published a proof of concept showing how to use WTSEnumerateProcessesA to enumerate processes, find a PID by process name, and extend the technique into DLL injection via CreateRemoteThread and LoadLibraryA. The post demonstrated the injection against mspaint.exe on Windows 10 22H2 x64 and said it successfully triggered a message box.
MITRE ATT&CK published its group page for CopyKittens (G0052), documenting the Iranian cyber-espionage group referenced in the material.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.