Astharot15 a58b47cb32 Add README content for COM Hijack details
Added details about COM Hijack targeting Chrome and Edge.
2026-07-12 15:31:01 +02:00
2026-07-12 15:22:00 +02:00
2026-07-12 15:22:00 +02:00

COM Hijack for CLSID {9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}

Interesting details

The hijack targets chrome and msedge; it also works in explorer, but it is likely to crash. The callback used is LdrCallEnclave. A Download function is commented out. It worked in the .exe compilation, but when compiled as a dll, it gets caught by AVs; so instead of using wininet, winhttp was used. The payload uses event objects for process synchronization rather than a traditional mutex. The COM object is very reliable; it has been working for 6 months without crashes.

S
Description
Automated archival mirror of github.com/Astharot15/COMLoaderAstharot
Readme 38 KiB
Languages
C++ 87.5%
C 12.5%