One Day Sec

What is the COM hijacking persistence technique used by APT group Trula against Outlook?

The technique, documented in Use COM Object hijacking to maintain persistence——Hijack Outlook, involves modifying two registry entries under HKCU\Software\Classes\CLSID to hijack COM objects that Outlook loads during startup. This forces Outlook to load a malicious DLL, requiring only current user permissions and making it a low-privilege persistence method favored by the Trula APT group.
COM hijackingpersistenceAPT TrulaOutlookDLL loadingHKCU registry

Browse all Q&A →