A series of public proof-of-concept posts detailed how attackers can establish persistence on Windows by abusing multiple native mechanisms, including AppInit_DLLs, COM hijacking, Windows services, logon scripts, file-association changes, uninstall handlers, Event Viewer help links, shell CLSID command handlers, and Accessibility Features such as Sticky Keys. The demonstrations showed malware-like code modifying keys under HKLM and HKCU to force execution at boot, logon, application launch, or user interaction, with several techniques requiring administrator privileges while others worked in the current user context.
The examples included replacing .txt open commands, setting HKCU\Environment\UserInitMprLogonScript, creating malicious InprocServer32 registrations for COM objects, altering UninstallString values for installed software, redirecting Event Viewer online help to a local executable, and using either Image File Execution Options or symbolic links to hijack sethc.exe. The posts also tied several methods to known threat activity, citing groups and malware such as APT28, APT39, Turla, Kimsuky, APT3, APT29, APT32, APT38, APT41, Ramsay, Attor, Zebrocy, Mosquito, and SILENTTRINITY as examples of similar persistence tradecraft seen in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The content states that malware using default file-association hijacking was used in a campaign against Croatian government agencies. The campaign is explicitly anchored only to 2019 and attributed to unidentified cyber actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.