Cybersecurity researchers at Deep Instinct have discovered a new lateral movement attack method based on the Distributed Component Object Model (DCOM) , which allows hackers to secretly install backdoors on Windows systems .

The technique exploits the Windows Installer service to remotely write custom DLLs (Dynamic Link Libraries), load them into an active service, and execute them with arbitrary parameters.
Read more: MirrorFace: Installs ANEL and NOOPDOOR Backdoors
The attack leverages the IMsiServer COM interface, exploiting its functions through reverse engineering, to remotely execute code and bypass traditional security measures. The hacker can also establish persistent access points on victims' systems.
The method involves the following steps: identifying the vulnerable Windows Installer service, exploiting the service's COM interface, creating a malicious DLL, remotely registering the DLL, loading it into a running process, and executing the code. Thanks to the extensive privileged capabilities of Windows Installer and its accessibility over a network, the hacker gains remote control of the service.
See also: WolfsBane: New Linux backdoor used by Chinese hackers Gelsemium
Despite its power, the method has limitations. Hackers and victims must be on the same domain, and the attack depends on the status of updated DCOM Hardening patches. In addition, the payload must be strongly signed and compatible with the system architecture (x86 or x64), which increases the difficulty.

Deep Instinct's research also includes analysis of the IDispatch interface, which allows scripting languages to interact with COM objects. However, the IMsiServer interface used in the attack does not support IDispatch, which precludes the use of traditional languages such as PowerShell.
Read more: Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor
Instead, the researchers used low-level techniques to directly call IMsiServer methods, achieving remote code execution.
Source: hackread
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
