[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHS2_2U3dqhw8HB9wO-Z1wXknU-EQAmqfss9WaM7pYAA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},711,"How does the Image File Execution Options technique redirect executable programs in Windows?","The Image File Execution Options technique modifies a registry key under `HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options` to redirect a target executable (e.g., notepad.exe) to a different program (e.g., calc.exe) by adding a Debugger string value. For example, starting notepad.exe would then execute calc.exe. As noted in the [Analysis of Windows Backdoor Exploitation Methods in CIA Vault7 RDB](\u002Fnews\u002Fanalysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb), antivirus software typically intercepts such registry modifications.","\u003Cp>The Image File Execution Options technique modifies a registry key under `HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options` to redirect a target executable (e.g., notepad.exe) to a different program (e.g., calc.exe) by adding a Debugger string value. For example, starting notepad.exe would then execute calc.exe. As noted in the [Analysis of Windows Backdoor Exploitation Methods in CIA Vault7 RDB](\u002Fnews\u002Fanalysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb), antivirus software typically intercepts such registry modifications.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-image-file-execution-options-technique-redirect-executable-programs-1777482317732","Image File Execution Options, IFEO, registry hijacking, Debugger, persistence, Windows backdoor",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},176,"Analysis of Windows Backdoor Exploitation Methods in CIA Vault7 RDB","analysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb","Analysis of Windows backdoor exploitation methods from CIA Vault7 RDB, including VBR persistence, registry hijacking, and DLL injection techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'CIA Hive Testing Guide – Source Code Acquisition and Brief Analysis', we studied the documents codenamed Vault 8 released by WikiLeaks, providing a brief analysis of the server remote control tool Hive.\u003C\u002Fp>\u003Cp>This article will continue analyzing the CIA-related materials released by WikiLeaks, introducing the Windows backdoor exploitation methods mentioned in the Remote Development Branch (RDB) of Vault 7.\u003C\u002Fp>\u003Cp>Material address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_2621760.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will analyze the following backdoor exploitation methods:\u003C\u002Fp>\u003Cul>\u003Cli>VBR Persistence\u003C\u002Fli>\u003Cli>Image File Execution Options\u003C\u002Fli>\u003Cli>OCI.DLL Service Persistence\u003C\u002Fli>\u003Cli>Shell Extension Persistence\u003C\u002Fli>\u003Cli>Windows FAX DLL Injection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VBR Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Used to execute backdoors during the Windows system startup process, capable of hooking kernel code\u003C\u002Fp>\u003Cp>VBR stands for Volume Boot Record (also known as the Partition Boot Record)\u003C\u002Fp>\u003Cp>The corresponding tool is Stolen Goods 2.0 (not publicly released)\u003C\u002Fp>\u003Cp>Documentation address for Stolen Goods:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fvault7\u002Fdocument\u002FStolenGoods-2_0-UserGuide\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Can load drivers during the Windows startup process (drivers do not require signatures)\u003C\u002Fli>\u003Cli>Compatible with WinXP (x86), Win7 (x86\u002Fx64)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This method is sourced from https:\u002F\u002Fgithub.com\u002Fhzeroo\u002FCarberp\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The source code included in https:\u002F\u002Fgithub.com\u002Fhzeroo\u002FCarberp is worth in-depth study\u003C\u002Fp>\u003Ch2>0x03 Image File Execution Options\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Redirecting executable programs through registry configuration\u003C\u002Fp>\u003Cp>Modification method (hijacking notepad.exe):\u003C\u002Fp>\u003Cp>Registry path:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\\u003C\u002Fp>\u003Cp>Create new key notepad.exe\u003C\u002Fp>\u003Cp>Create new string value, name: notepad.exe, path \"C:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003Cp>Corresponding cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\notepad.exe\" \u002Fv Debugger \u002Ft REG_SZ \u002Fd \"C:\\windows\\system32\\calc.exe\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When starting notepad.exe, the actual executed program is \"C:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Typically, modifying registry at this location will be intercepted by antivirus software\u003C\u002Fp>\u003Ch2>0x04 OCI.DLL Service Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Utilizing MSDTC service to load dll for achieving auto-start\u003C\u002Fp>\u003Cp>A backdoor used by Shadow Force in domain environments, documentation suggests CIA also discovered this method can be used in non-domain environments\u003C\u002Fp>\u003Cp>I introduced this exploitation method in a previous article, the address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsome-open-source-project\u002FUse-msdtc-to-maintain-persistence\u002F\u003C\u002Fp>\u003Cp>The method used in my article is to save the dll in C:\\Windows\\System32\\\u003C\u002Fp>\u003Cp>The method used by the CIA is to save the dll in C:\\Windows\\System32\\wbem\\\u003C\u002Fp>\u003Cp>Both locations are viable; the MSDTC service will search these two locations in sequence upon startup\u003C\u002Fp>\u003Ch2>0x05 Shell Extension Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Hijacking the startup process of explorer.exe via COM dll\u003C\u002Fp>\u003Cp>I have also introduced this approach in a previous article, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsome-open-source-project\u002FUse-COM-Object-hijacking-to-maintain-persistence-Hijack-explorer.exe\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method has been used by several well-known malware, such as COMRAT, ZeroAccess rootkit, and BBSRAT\u003C\u002Fp>\u003Ch2>0x06 Windows FAX DLL Injection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Hijacking Explorer.exe's loading of fxsst.dll through DLL hijacking\u003C\u002Fp>\u003Cp>Explorer.exe loads c:\\Windows\\System32\\fxsst.dll at startup (service enabled by default for fax services)\u003C\u002Fp>\u003Cp>Saving payload.dll as c:\\Windows\\fxsst.dll enables DLL hijacking, hijacking Explorer.exe's loading of fxsst.dll\u003C\u002Fp>\u003Cp>An earlier publicly disclosed exploitation method, reference link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Froom362.com\u002Fpost\u002F2011\u002F2011-06-27-fxsstdll-persistence-the-evil-fax-machine\u002F\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the Windows backdoor exploitation methods mentioned in the Remote Development Branch (RDB) of Vault7, showing that this content draws on publicly disclosed exploitation methods\u003C\u002Fp>\u003Cp>I have systematically collected publicly disclosed Windows backdoor exploitation methods (including my own disclosed methods), address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:38:21.203Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"CIA Vault7 Windows Backdoor Exploitation Methods Analysis","CIA Vault7, Windows backdoor, exploitation methods, persistence, RDB, WikiLeaks, VBR, Image File Execution Options, OCI.DLL, Shell Extension, FAX DLL injection",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4,45],714,713,712,710,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.115Z","2026-07-23T16:01:59.799Z","draft","2026-07-23T16:14:20.519Z"]