LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1546.015: Component Object Model Hijacking

Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects. COM is a system within Windows to enable interaction between software components through the operating system.[1] References to various COM objects are stored in the Registry.

Adversaries may use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence. Hijacking a COM object requires a change in the Registry to replace a reference to a legitimate system component which may cause that component to not work when executed. When that system component is executed through normal system operation the adversary's code will be executed instead.[2] An adversary is likely to hijack objects that are used frequently enough to maintain a consistent level of persistence, but are unlikely to break noticeable functionality within the system as to avoid system instability that could lead to detection.

One variation of COM hijacking involves abusing Type Libraries (TypeLibs), which provide metadata about COM objects, such as their interfaces and methods. Adversaries may modify Registry keys associated with TypeLibs to redirect legitimate COM object functionality to malicious scripts or payloads. Unlike traditional COM hijacking, which commonly uses local DLLs, this variation may leverage the "script:" moniker to execute remote scripts hosted on external servers.[3] This approach enables stealthy execution of code while maintaining persistence, as the remote payload would be automatically downloaded whenever the hijacked COM object is accessed.

EnterpriseT1546.015Sub-techniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

COM hijacking matters because it turns normal Windows component loading into a persistence or privilege-escalation opportunity. A small Registry change can cause trusted Windows or application activity to load adversary-controlled code instead of the expected COM component, potentially making the activity blend into routine endpoint behavior.

Executive priority

Prioritize this as a Windows endpoint resilience and incident-readiness issue. Leaders should ask whether the organization can prove who changed COM-related Registry keys, whether suspicious DLL loads can be correlated back to those changes, and whether SOC playbooks treat COM hijacking as a persistence mechanism during containment and eradication. The ATT&CK relationships to APT28 and multiple malware/RAT families make this a useful control-validation scenario, but they do not by themselves indicate current exposure or active targeting.

Technical view

For SOC and IR teams, validate visibility on Windows Registry locations used for COM object and TypeLib references, then correlate changes with subsequent process execution and DLL loads. The related detection strategy, DET0481, specifically points to Registry and DLL load correlation. Pay attention to TypeLib abuse and use of the "script:" moniker described in the ATT&CK text, where a hijacked COM reference may retrieve a remote script when the object is accessed. Because legitimate software also uses COM extensively, detection should focus on unusual changes, unexpected paths, suspicious script references, and execution chains that differ from known-good baselines.

Likely telemetry

  • Windows Registry modification events for COM object and TypeLib references
  • Process creation events around applications that instantiate COM objects
  • DLL load telemetry tied to processes using COM components
  • File creation or modification events for newly referenced DLLs or payloads
  • Network telemetry for remote script retrieval when TypeLib or script moniker behavior is suspected

Detection direction

  • Baseline common COM and TypeLib Registry references on managed Windows systems and alert on unexpected changes.
  • Correlate Registry changes with later DLL loads or script execution from the affected host, as suggested by DET0481.
  • Tune detections to reduce noise from legitimate software installation, update, and repair activity that modifies COM registrations.
  • Investigate COM references pointing to unusual user-writable paths, unexpected DLLs, or remote script-style references where visible.
  • During IR, check COM hijacking when persistence remains after obvious startup folders, services, and scheduled tasks have been cleared.

Mitigation priorities

  • Limit unnecessary ability to modify sensitive Windows Registry locations through least privilege and administrative change control.
  • Maintain endpoint baselines for COM-related Registry keys so unauthorized drift can be identified.
  • Use controlled software deployment and update processes to distinguish expected COM registration changes from suspicious ones.
  • Ensure EDR or endpoint logging captures Registry, process, module-load, and relevant network evidence needed to reconstruct the behavior.
  • Include COM hijacking checks in persistence-hunting and post-containment validation procedures.
Additional notes and limits

This is a Windows sub-technique under Event Triggered Execution for persistence and privilege escalation. ATT&CK provides no official detection text for this object, but the supplied relationship to DET0481 gives a clear validation path: correlate COM-related Registry changes with DLL loading behavior. Related software includes JHUHUGIT, ADVSTORESHELL, ComRAT, BBSRAT, Mosquito, KONNI, WarzoneRAT, Ferocious, SILENTTRINITY, PcShare, and SVCReady.

The supplied ATT&CK fields do not provide official mitigations, specific Registry paths, guaranteed indicators, or organization-specific false-positive patterns. Local Windows build, installed software, administrative practices, and endpoint telemetry quality determine whether this can be detected reliably.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Component Object Model Hijacking

Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects. COM is a system within Windows to enable interaction between software components through the operating system.[1] References to various COM objects are stored in the Registry.

Adversaries may use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence. Hijacking a COM object requires a change in the Registry to replace a reference to a legitimate system component which may cause that component to not work when executed. When that system component is executed through normal system operation the adversary's code will be executed instead.[2] An adversary is likely to hijack objects that are used frequently enough to maintain a consistent level of persistence, but are unlikely to break noticeable functionality within the system as to avoid system instability that could lead to detection.

One variation of COM hijacking involves abusing Type Libraries (TypeLibs), which provide metadata about COM objects, such as their interfaces and methods. Adversaries may modify Registry keys associated with TypeLibs to redirect legitimate COM object functionality to malicious scripts or payloads. Unlike traditional COM hijacking, which commonly uses local DLLs, this variation may leverage the "script:" moniker to execute remote scripts hosted on external servers.[3] This approach enables stealthy execution of code while maintaining persistence, as the remote payload would be automatically downloaded whenever the hijacked COM object is accessed.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1546Event Triggered ExecutionThis object subtechnique of Event Triggered Execution.
EnterpriseT1122Component Object Model HijackingComponent Object Model Hijacking revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

MalwareEnterprise

S0045: ADVSTORESHELL

ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase. [1] [2]

Windows
MalwareEnterprise

S0356: KONNI

KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014. KONNI has significant code overlap with the NOKKI malware family, and has been linked to several suspected North Korean campaigns targeting political organizations in Russia, East Asia, Europe and the Middle East; there is some evidence potentially linking KONNI to APT37.[1][2][3][4][5]

Windows
ToolEnterprise

S1050: PcShare

PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream campaign since late 2018.[1][2]

Windows
MalwareEnterprise

S0670: WarzoneRAT

WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.[1][2]

Windows
MalwareEnterprise

S0126: ComRAT

ComRAT is a second stage implant suspected of being a descendant of Agent.btz and used by Turla. The first version of ComRAT was identified in 2007, but the tool has undergone substantial development for many years since.[1][2][3]

Windows
MalwareEnterprise

S1064: SVCReady

SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns. Security researchers have noted overlaps between TA551 activity and SVCReady distribution, including similarities in file names, lure images, and identical grammatical errors.[1]

Windows
MalwareEnterprise

S0256: Mosquito

Mosquito is a Win32 backdoor that has been used by Turla. Mosquito is made up of three parts: the installer, the launcher, and the backdoor. The main backdoor is called CommanderDLL and is launched by the loader program. [1]

Windows
MalwareEnterprise

S0127: BBSRAT

BBSRAT is malware with remote access tool functionality that has been used in targeted compromises. [1]

Windows
ToolEnterprise

S0692: SILENTTRINITY

SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.[1][2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
b50e88b1a0b41045...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundleb50e88b1a0b4…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Component Object Model

    Microsoft. (n.d.). The Component Object Model. Retrieved August 18, 2016.

    Open source URL
  2. [2]
    GDATA COM Hijacking

    G DATA. (2014, October). COM Object hijacking: the discreet way of persistence. Retrieved August 13, 2016.

    Open source URL
  3. [3]
    RELIAQUEST

    RELIAQUEST THREAT RESEARCH TEAM. (2025, April 11). Threat Spotlight: Hijacked and Hidden: New Backdoor and Persistence Technique. Retrieved June 27, 2025.

    Open source URL
  4. [4]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  5. [5]
    Medium KONNI Jan 2020

    Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.

    Open source URL
  6. [6]
    ESET Sednit Part 1

    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

  7. [7]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  8. [8]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  9. [9]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  10. [10]
    NorthSec 2015 GData Uroburos Tools

    Rascagneres, P. (2015, May). Tools used by the Uroburos actors. Retrieved August 18, 2016.

    Open source URL
  11. [11]
    HP SVCReady Jun 2022

    Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

    Open source URL
  12. [12]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  13. [13]
    Kaspersky WIRTE November 2021

    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

    Open source URL
  14. [14]
    Palo Alto Networks BBSRAT

    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

  15. [15]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  16. [16]
    Talos Seduploader Oct 2017

    Mercer, W., et al. (2017, October 22). "Cyber Conflict" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.

    Open source URL
  17. [17]
    Elastic COM Hijacking

    Ewing, P. Strom, B. (2016, September 15). How to Hunt: Detecting Persistence & Evasion with the COM. Retrieved September 15, 2016.

    Open source URL
  18. [18]
    Elastic COM Hijacking

    Ewing, P. Strom, B. (2016, September 15). How to Hunt: Detecting Persistence & Evasion with the COM. Retrieved September 15, 2016.

    Open source URL
  19. [19]
    Elastic COM Hijacking

    Ewing, P. Strom, B. (2016, September 15). How to Hunt: Detecting Persistence & Evasion with the COM. Retrieved September 15, 2016.

    Open source URL
  20. [20]
    GDATA COM Hijacking

    G DATA. (2014, October). COM Object hijacking: the discreet way of persistence. Retrieved August 13, 2016.

    Open source URL
  21. [21]
    GDATA COM Hijacking

    G DATA. (2014, October). COM Object hijacking: the discreet way of persistence. Retrieved August 13, 2016.

    Open source URL
  22. [22]
    Microsoft Component Object Model

    Microsoft. (n.d.). The Component Object Model. Retrieved August 18, 2016.

    Open source URL
  23. [23]
    Microsoft Component Object Model

    Microsoft. (n.d.). The Component Object Model. Retrieved August 18, 2016.

    Open source URL
  24. [24]
    RELIAQUEST

    RELIAQUEST THREAT RESEARCH TEAM. (2025, April 11). Threat Spotlight: Hijacked and Hidden: New Backdoor and Persistence Technique. Retrieved June 27, 2025.

    Open source URL
  25. [25]
    RELIAQUEST

    RELIAQUEST THREAT RESEARCH TEAM. (2025, April 11). Threat Spotlight: Hijacked and Hidden: New Backdoor and Persistence Technique. Retrieved June 27, 2025.

    Open source URL
  26. [26]
    mitre-attackT1546.015
    Open source URL
  27. [27]
    mitre-attackT1546.015
    Open source URL
  28. [28]
    mitre-attackT1546.015
    Open source URL
  29. [29]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  30. [30]
    Medium KONNI Jan 2020

    Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.

    Open source URL
  31. [31]
    ESET Sednit Part 1

    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

  32. [32]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  33. [33]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  34. [34]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  35. [35]
    NorthSec 2015 GData Uroburos Tools

    Rascagneres, P. (2015, May). Tools used by the Uroburos actors. Retrieved August 18, 2016.

    Open source URL
  36. [36]
    HP SVCReady Jun 2022

    Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

    Open source URL
  37. [37]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  38. [38]
    Kaspersky WIRTE November 2021

    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

    Open source URL
  39. [39]
    Palo Alto Networks BBSRAT

    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

  40. [40]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  41. [41]
    ESET Sednit Part 1

    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

  42. [42]
    ESET Sednit Part 1

    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

  43. [43]
    Talos Seduploader Oct 2017

    Mercer, W., et al. (2017, October 22). "Cyber Conflict" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.