[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvZjgeo1UKey7bUtFw7ykT9LurR4Q18hk7hwQ3JrXwIc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},467,"Can the MSDTC backdoor be exploited in a workgroup environment or only in a domain?","The MSDTC service starts by default in both domain and workgroup environments, so the backdoor works regardless of whether the computer is joined to a domain. This expands its applicability beyond the initial domain-focused attack described by Trend Micro, making it a versatile persistence method.","\u003Cp>The MSDTC service starts by default in both domain and workgroup environments, so the backdoor works regardless of whether the computer is joined to a domain. This expands its applicability beyond the initial domain-focused attack described by Trend Micro, making it a versatile persistence method.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-msdtc-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","can-the-msdtc-backdoor-be-exploited-in-a-workgroup-environment-or-only-in-a-doma-1777483503173","workgroup, domain environment, MSDTC service, default startup",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},117,"Use msdtc to maintain persistence","use-msdtc-to-maintain-persistence","Learn how MSDTC service DLL hijacking enables persistence, bypasses Autoruns, and methods for detection and defense in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>---\u003C\u002Fp>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A backdoor previously used by Shadow Force in a domain environment, leveraging the MSDTC service to load a DLL for achieving persistence and bypassing Autoruns' detection of startup items. This article will test it, introduce more exploitation techniques, and analyze defense methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to MSDTC\u003C\u002Fli>\u003Cli>Backdoor Concept\u003C\u002Fli>\u003Cli>Backdoor Verification\u003C\u002Fli>\u003Cli>More Testing and Exploitation Methods\u003C\u002Fli>\u003Cli>Detection and Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to MSDTC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>MSDTC:\u003C\u002Fh3>\u003Cul>\u003Cli>Corresponding service MSDTC, full name Distributed Transaction Coordinator, this service is started by default in Windows systems\u003C\u002Fli>\u003Cli>Corresponding process msdtc.exe, located at %windir%\\system32\\\u003C\u002Fli>\u003Cli>msdtc.exe is the Microsoft Distributed Transaction Coordinator, this process invokes the system's Microsoft Personal Web Server and Microsoft SQL Server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Backdoor Concept\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblog.trendmicro.com\u002Ftrendlabs-security-intelligence\u002Fshadow-force-uses-dll-hijacking-targets-south-korean-company\u002F\u003C\u002Fp>\u003Cp>The concept introduced in the article is as follows:\u003C\u002Fp>\u003Cp>When a computer joins a domain and the MSDTC service starts, it searches the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\MSDTC\\MTxOCI\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017971471_0_366ce87e92.jpeg\">\u003C\u002Fp>\u003Cp>It loads three DLLs respectively: oci.dll, SQLLib80.dll, xa80.dll\u003C\u002Fp>\u003Cp>However, notably,\u003Cstrong>Windows systems do not include oci.dll by default\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>That is to say, rename payload.dll to oci.dll and save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>When the MSDTC service starts on computers in the domain, it will load this dll to achieve code execution\u003C\u002Fp>\u003Ch2>0x04 Backdoor Verification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: Win7 x64\u003C\u002Fp>\u003Cp>Set up the domain environment, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017982877_1_6f1aec569e.jpeg\">\u003C\u002Fp>\u003Cp>Use Procmon to monitor the startup process of msdtc, filter the process msdtc.exe, and view file operations, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017987633_2_ae678245f6.jpeg\">\u003C\u002Fp>\u003Cp>msdtc.exe does indeed attempt to load oci.dll, and since oci.dll does not exist by default in the system, the loading fails\u003C\u002Fp>\u003Cp>Use a 64-bit test dll, download link as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>Terminate the process msdtc.exe, command line parameters as follows:\u003C\u002Fp>\u003Cp>taskkill \u002Ff \u002Fim msdtc.exe\u003C\u002Fp>\u003Cp>Waiting for msdtc.exe to restart\u003C\u002Fp>\u003Cp>After waiting for a while, mstdc.exe restarts and successfully loads oci.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992672_3_a32691e0e1.jpeg\">\u003C\u002Fp>\u003Cp>calc.exe starts with system privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996441_4_babee811c6.jpeg\">\u003C\u002Fp>\u003Cp>In actual testing, this method occasionally has bugs; after ending the process via taskkill, msdtc.exe does not restart\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simply restart the MSDTC service, command line parameters are as follows:\u003C\u002Fp>\u003Cp>net start msdtc\u003C\u002Fp>\u003Ch2>0x05 More Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Testing on 32-bit systems\u003C\u002Fh3>\u003Cp>For 32-bit systems, simply use the 32-bit dll, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Testing 64-bit systems\u003C\u002Fh3>\u003Cp>In 64-bit systems, although the SysWOW64 folder contains the 32-bit msdtc.exe, the MSDTC service only launches the 64-bit msdtc.exe\u003C\u002Fp>\u003Cp>Therefore, loading the 32-bit oci.dll is not supported\u003C\u002Fp>\u003Ch3>3. General testing\u003C\u002Fh3>\u003Cp>Actual testing shows that the MSDTC service is not exclusive to domain environments; it also starts by default in workgroup environments\u003C\u002Fp>\u003Cp>This means the exploitation method is applicable not only to domain environments but also to workgroup environments\u003C\u002Fp>\u003Ch3>4. Loading oci.dll with administrator privileges (privilege reduction startup)\u003C\u002Fh3>\u003Cp>The above method loads oci.dll with system privileges. Here is a method to load oci.dll with administrator privileges (privilege reduction startup):\u003C\u002Fp>\u003Cp>Execute in an administrator command prompt:\u003C\u002Fp>\u003Cp>msdtc -install\u003C\u002Fp>\u003Cp>The launched calc.exe runs with high privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017999418_5_e2b1780688.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For reasons why privilege reduction is needed and more implementation methods, refer to the article\u003C\u002Fp>\u003Cp>《Penetration Techniques – Privilege Reduction Startup of Programs》\u003C\u002Fp>\u003Ch2>0x06 Detection and Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Detection:\u003C\u002Fh3>\u003Cp>Check if %windir%\\system32\\ contains suspicious oci.dll\u003C\u002Fp>\u003Ch3>Defense:\u003C\u002Fh3>\u003Cp>For regular user hosts, it is recommended to disable the MSDTC service\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces exploitation techniques related to MSDTC, which can not only be used as a backdoor but also for launching programs with reduced privileges.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>---\u003C\u002Fp>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A backdoor previously used by Shadow Force in a domain environment, leveraging the MSDTC service to load a DLL for achieving persistence and bypassing Autoruns' detection of startup items. This article will test it, introduce more exploitation techniques, and analyze defense methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to MSDTC\u003C\u002Fli>\u003Cli>Backdoor Concept\u003C\u002Fli>\u003Cli>Backdoor Verification\u003C\u002Fli>\u003Cli>More Testing and Exploitation Methods\u003C\u002Fli>\u003Cli>Detection and Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to MSDTC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>MSDTC:\u003C\u002Fh3>\u003Cul>\u003Cli>Corresponding service MSDTC, full name Distributed Transaction Coordinator, this service is started by default in Windows systems\u003C\u002Fli>\u003Cli>Corresponding process msdtc.exe, located at %windir%\\system32\\\u003C\u002Fli>\u003Cli>msdtc.exe is the Microsoft Distributed Transaction Coordinator, this process invokes the system's Microsoft Personal Web Server and Microsoft SQL Server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Backdoor Concept\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblog.trendmicro.com\u002Ftrendlabs-security-intelligence\u002Fshadow-force-uses-dll-hijacking-targets-south-korean-company\u002F\u003C\u002Fp>\u003Cp>The concept introduced in the article is as follows:\u003C\u002Fp>\u003Cp>When a computer joins a domain and the MSDTC service starts, it searches the registry HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\MSDTC\\MTxOCI\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017971471_0_366ce87e92-1.jpeg\">\u003C\u002Fp>\u003Cp>It loads three DLLs respectively: oci.dll, SQLLib80.dll, xa80.dll\u003C\u002Fp>\u003Cp>However, notably,\u003Cstrong>Windows systems do not include oci.dll by default\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>That is to say, rename payload.dll to oci.dll and save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>When the MSDTC service starts on computers in the domain, it will load this dll to achieve code execution\u003C\u002Fp>\u003Ch2>0x04 Backdoor Verification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: Win7 x64\u003C\u002Fp>\u003Cp>Set up the domain environment, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017982877_1_6f1aec569e-1.jpeg\">\u003C\u002Fp>\u003Cp>Use Procmon to monitor the startup process of msdtc, filter the process msdtc.exe, and view file operations, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017987633_2_ae678245f6-1.jpeg\">\u003C\u002Fp>\u003Cp>msdtc.exe does indeed attempt to load oci.dll, and since oci.dll does not exist by default in the system, the loading fails\u003C\u002Fp>\u003Cp>Use a 64-bit test dll, download link as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Save it under %windir%\\system32\\\u003C\u002Fp>\u003Cp>Terminate the process msdtc.exe, command line parameters as follows:\u003C\u002Fp>\u003Cp>taskkill \u002Ff \u002Fim msdtc.exe\u003C\u002Fp>\u003Cp>Waiting for msdtc.exe to restart\u003C\u002Fp>\u003Cp>After waiting for a while, mstdc.exe restarts and successfully loads oci.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992672_3_a32691e0e1-1.jpeg\">\u003C\u002Fp>\u003Cp>calc.exe starts with system privileges\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996441_4_babee811c6-1.jpeg\">\u003C\u002Fp>\u003Cp>In actual testing, this method occasionally has bugs; after ending the process via taskkill, msdtc.exe does not restart\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simply restart the MSDTC service, command line parameters are as follows:\u003C\u002Fp>\u003Cp>net start msdtc\u003C\u002Fp>\u003Ch2>0x05 More Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Testing on 32-bit systems\u003C\u002Fh3>\u003Cp>For 32-bit systems, simply use the 32-bit dll, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Testing 64-bit systems\u003C\u002Fh3>\u003Cp>In 64-bit systems, although the SysWOW64 folder contains the 32-bit msdtc.exe, the MSDTC service only launches the 64-bit msdtc.exe\u003C\u002Fp>\u003Cp>Therefore, loading the 32-bit oci.dll is not supported\u003C\u002Fp>\u003Ch3>3. General testing\u003C\u002Fh3>\u003Cp>Actual testing shows that the MSDTC service is not exclusive to domain environments; it also starts by default in workgroup environments\u003C\u002Fp>\u003Cp>This means the exploitation method is applicable not only to domain environments but also to workgroup environments\u003C\u002Fp>\u003Ch3>4. Loading oci.dll with administrator privileges (privilege reduction startup)\u003C\u002Fh3>\u003Cp>The above method loads oci.dll with system privileges. Here is a method to load oci.dll with administrator privileges (privilege reduction startup):\u003C\u002Fp>\u003Cp>Execute in an administrator command prompt:\u003C\u002Fp>\u003Cp>msdtc -install\u003C\u002Fp>\u003Cp>The launched calc.exe runs with high privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017999418_5_e2b1780688-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For reasons why privilege reduction is needed and more implementation methods, refer to the article\u003C\u002Fp>\u003Cp>《Penetration Techniques – Privilege Reduction Startup of Programs》\u003C\u002Fp>\u003Ch2>0x06 Detection and Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Detection:\u003C\u002Fh3>\u003Cp>Check if %windir%\\system32\\ contains suspicious oci.dll\u003C\u002Fp>\u003Ch3>Defense:\u003C\u002Fh3>\u003Cp>For regular user hosts, it is recommended to disable the MSDTC service\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces exploitation techniques related to MSDTC, which can not only be used as a backdoor but also for launching programs with reduced privileges.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1115,"Onedaysec",3,"published","2026-02-02T07:51:00.067Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"MSDTC Backdoor: Persistence via DLL Hijacking & Defense","MSDTC backdoor, DLL hijacking, persistence, Windows security, domain environment, detection, defense, Shadow Force, oci.dll",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],470,469,468,466,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.150Z","2026-07-23T16:01:37.818Z","draft","2026-07-23T16:12:32.820Z"]