HomeSecurityBitlockMove Tool Allows Lateral Movement & COM Hijacking

BitlockMove Tool Allows Lateral Movement & COM Hijacking

A new PoC tool called BitlockMove demonstrates a new lateral movement technique that exploits BitLocker's Distributed Component Object Model (DCOM) interfaces and COM hijacking

See also: Microsoft warns of vulnerability in Active Directory Domain Services

BitlockMove

The BitlockMove tool was released by security researcher Fabian Mosch of r-tec Cyber ​​Security and allows attackers to execute code on remote systems within the session of an already logged in user, bypassing the need to steal credentials or impersonate accounts.

BitlockMove exploits how certain COM classes, when configured as “INTERACTIVE USER“, can create a process within the context of the current user session. If these processes are also vulnerable to COM hijacking, an attacker can remotely modify the registry, deliver a malicious DLL via Server Message Block (SMB) , and trigger its execution via DCOM.

This technique is particularly silent because the malicious code is executed directly in the context of the target user, creating fewer indicators of compromise compared to traditional methods such as LSASS credential theft

The PoC specifically targets the BDEUILauncher (CLSID ab93b6f1-be76-4185-a488-a9001b105b94), which can launch several processes. One of them, BaaUpdate.exe, is vulnerable to COM hijacking when launched with certain parameters.

See also: Windows BitLocker vulnerability allows privilege escalation attack

CHwapi- Windows BitLocker-hospital Belgium

The BitlockMove tool grabs a relative CLSID (A7A63E5C-3877-4840-8727-C1EA9D7A4D50) from the remote system. Since BitLocker is most often enabled on Windows client operating systems, this lateral movement technique is primarily effective against workstations rather than servers. The tool, written in C#, operates in two distinct modes: reconnaissance and attack.

In Recognition Mode, an attacker can identify active user sessions on a target, allowing the threat actor to select a highly privileged user, such as a domain administrator, for the attack.

In Attack Mode, the tool executes the attack. The attacker specifies the target, the username of the active session, a path to drop the malicious DLL, and the command to execute. The tool then executes the remote COM hijack, activates the payload, and cleans up by removing the hijack from the registry and deleting the DLL.

Security researchers can detect this technique by monitoring for specific behaviors. Key indicators include remote COM hijacking of the targeted BitLocker-related CLSID, followed by the BaaUpdate.exe loading a new DLL from the hijacked location. Subprocesses spawned by BaaUpdate.exe or BdeUISrv.exe are also strong signs of compromise. Security teams can create queries to look for the presence of the BdeUISrv.exe process, as its legitimate use is rare.

See also: ShrinkLocker ransomware: Free decryption tool

BitlockMove Tool Allows Lateral Movement & COM Hijacking
BitlockMove Tool Allows Lateral Movement & COM Hijacking

The PoC uses a predefined DLL, making signature-based detection simple. However, attackers can easily create custom DLLs to evade such defenses.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS