Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
Detects suspicious modifications to a PSFactory COM InProcServer32 (Default) registry value that may enable COM-based persistence.
- Product
- windows
- Category
- registry_set
- Author
- BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2023-06-07
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags changes to the PSFactory COM CLSID InProcServer32 (Default) registry value. COM in-proc server hijacking can provide persistence by redirecting a CLSID to load an attacker-controlled DLL instead of the expected binary. It relies on registry set telemetry for the specific CLSID path and filters out updates that point to the known ActXPrxy.dll locations.
Reporting behind it
- blogs.blackberry.comhttps://blogs.blackberry.com/en/2023/06/romcom-resurfaces-targeting-ukraine
- strontic.github.iohttps://strontic.github.io/xcyclopedia/library/clsid_C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6.html
- virustotal.comhttps://www.virustotal.com/gui/file/6d3ab9e729bb03ae8ae3fcd824474c5052a165de6cb4c27334969a542c7b261d/detection
- trendmicro.comhttps://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_comhijack_psfactorybuffer.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
id: 402617c4-67a2-413a-b8ef-badca4b5442d
status: test
description: This rule flags changes to the PSFactory COM CLSID InProcServer32 (Default) registry value. COM in-proc server hijacking can provide persistence by redirecting a CLSID to load an attacker-controlled DLL instead of the expected binary. It relies on registry set telemetry for the specific CLSID path and filters out updates that point to the known ActXPrxy.dll locations.
references:
- https://blogs.blackberry.com/en/2023/06/romcom-resurfaces-targeting-ukraine
- https://strontic.github.io/xcyclopedia/library/clsid_C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6.html
- https://www.virustotal.com/gui/file/6d3ab9e729bb03ae8ae3fcd824474c5052a165de6cb4c27334969a542c7b261d/detection
- https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_comhijack_psfactorybuffer.yml
author: BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-07
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1546.015
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|endswith: \CLSID\{c90250f3-4d7d-4991-9b69-a5c5bc1c2ae6}\InProcServer32\(Default)
filter_main:
Details:
- "%windir%\\System32\\ActXPrxy.dll"
- C:\Windows\System32\ActXPrxy.dll
condition: selection and not filter_main
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 243380fa-11eb-4141-af92-e14925e77c1b
type: derived