A new PoC tool called BitlockMove demonstrates a new lateral movement technique that exploits BitLocker's Distributed Component Object Model (DCOM) interfaces and COM hijacking
See also: Microsoft warns of vulnerability in Active Directory Domain Services

The BitlockMove tool was released by security researcher Fabian Mosch of r-tec Cyber Security and allows attackers to execute code on remote systems within the session of an already logged in user, bypassing the need to steal credentials or impersonate accounts.
BitlockMove exploits how certain COM classes, when configured as “INTERACTIVE USER“, can create a process within the context of the current user session. If these processes are also vulnerable to COM hijacking, an attacker can remotely modify the registry, deliver a malicious DLL via Server Message Block (SMB) , and trigger its execution via DCOM.
This technique is particularly silent because the malicious code is executed directly in the context of the target user, creating fewer indicators of compromise compared to traditional methods such as LSASS credential theft
The PoC specifically targets the BDEUILauncher (CLSID ab93b6f1-be76-4185-a488-a9001b105b94), which can launch several processes. One of them, BaaUpdate.exe, is vulnerable to COM hijacking when launched with certain parameters.
See also: Windows BitLocker vulnerability allows privilege escalation attack

The BitlockMove tool grabs a relative CLSID (A7A63E5C-3877-4840-8727-C1EA9D7A4D50) from the remote system. Since BitLocker is most often enabled on Windows client operating systems, this lateral movement technique is primarily effective against workstations rather than servers. The tool, written in C#, operates in two distinct modes: reconnaissance and attack.
In Recognition Mode, an attacker can identify active user sessions on a target, allowing the threat actor to select a highly privileged user, such as a domain administrator, for the attack.
In Attack Mode, the tool executes the attack. The attacker specifies the target, the username of the active session, a path to drop the malicious DLL, and the command to execute. The tool then executes the remote COM hijack, activates the payload, and cleans up by removing the hijack from the registry and deleting the DLL.
Security researchers can detect this technique by monitoring for specific behaviors. Key indicators include remote COM hijacking of the targeted BitLocker-related CLSID, followed by the BaaUpdate.exe loading a new DLL from the hijacked location. Subprocesses spawned by BaaUpdate.exe or BdeUISrv.exe are also strong signs of compromise. Security teams can create queries to look for the presence of the BdeUISrv.exe process, as its legitimate use is rare.
See also: ShrinkLocker ransomware: Free decryption tool

The PoC uses a predefined DLL, making signature-based detection simple. However, attackers can easily create custom DLLs to evade such defenses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
