How Windows Malware Uses COM—and How Analysts Can Analyze It

Summary
Talos explains how Windows malware uses COM for functions such as persistence, execution, and data transfer, and shows how analysts can identify COM classes, interfaces, and methods in binaries.
Key points
- Malware uses COM to access Windows functionality for persistence, execution, system discovery, file transfer, and other activity; DCOM can extend object access across a network.
- COM activity can be obscured by GUIDs and indirect vtable calls, making class, interface, and method identification useful in binary analysis.
- Analysts can map CLSIDs and IIDs using registry data and tools such as OleView.NET, ComView, and IDA’s COM Helper, then apply interface types to clarify indirect calls.
- Talos illustrates the workflow with Qakbot’s use of WMI, Gh0stRAT’s scheduled-task creation, Attor’s BITS transfers, and WarmCookie’s Task Scheduler persistence.
- YARA hunting can search for COM GUIDs and related APIs, but rules need additional context because they may also match legitimate software.
- COM activity may not appear as an obvious command-line process launch, so analysts can use static analysis or runtime tracing to investigate it.
Article Details
- Topic
- Malware abuse of Windows COM and DCOM interfaces and practical reverse-engineering methods for identifying COM functionality
MITRE ATT&CK
T1021.003 · Distributed Component Object ModelThe article explicitly identifies DCOM remote activation and method invocation as Remote Services: Distributed Component Object Model.T1053.005 · Scheduled TaskGh0stRAT/SimpleRemoter creates scheduled tasks through COM; WarmCookie uses Task Scheduler COM interfaces for persistence.T1197 · BITS JobsAn Attor plugin uses IBackgroundCopyJob to communicate with a C2 server through BITS.T1518.001 · Security Software DiscoveryAn Attor plugin uses IWbemClassObject to enumerate installed endpoint security software.T1559.001 · Component Object ModelMalware uses COM interfaces to invoke Windows functionality, including script execution and automation.
People
David ZimmerTalos researcher who wrote DispatchLogger for tracing COM-related calls.Frank BoldewinAuthor of COM Code Helper scripts recommended for COM reverse engineering.James ForshawDeveloper of OleView.NET and credited source for COM and DCOM architecture illustrations.Vanja SvajcerAuthor of the article on COM usage by Windows threats.
Malware
AttorFigure 14. Gh0stRAT/SimpleRemoter code creating a scheduled task through Task Scheduler COM interfaces.Case study 2: Attor and BITS BadSpaceWarmCookie, also known as BadSpace, is a malware family that Talos reported as emerging in April 2024 and being distributed through malspam and malvertising. Gh0stRATCase study 1: Gh0stRAT/SimpleRemoter and Task Scheduler PinkslipbotQakbot, also known as Qbot or Pinkslipbot, is a long-running modular banking trojan that has been active since at least 2007 and evolved into a general-purpose malware delivery platform used by financially motivatedQakbotFigure 7. IDA Pro analysis of a Task Scheduler COM example. Reconstructing the vtable lets the analyst map indirect calls to method names. Applying the workflow to a Qakbot DLL QbotQakbot, also known as Qbot or Pinkslipbot, is a long-running modular banking trojan that has been active since at least 2007 and evolved into a general-purpose malware delivery platform used by financially motivatedSimpleRemoterCase study 1: Gh0stRAT/SimpleRemoter and Task Scheduler WarmCookieOlder Task Scheduler 1.0 samples may instead use the ITaskScheduler interface, which appears in the WarmCookie case study below.
Vendors
Products
Tools
Binary Ninjaplugin, and Airbus CERT’s COMIDA and Frank Boldewin’s COM Code Helper scripts are also useful options. Binary Ninja users can apply similar type reconstruction workflows to make interface pointers and vtable callsCOM Code Helperprocess. IDA includes a default COM Helper plugin, and Airbus CERT’s COMIDA and Frank Boldewin’s COM Code Helper scripts are also useful options. Binary Ninja users can apply similar type reconstruction workflowsCOM Helperreverse-engineering tool that maps GUIDs to human-readable code. For example, in IDA Pro, the standard COM Helper can identify relevant class and interface IDs and rename locations in the database. COMIDAand scripts can accelerate this process. IDA includes a default COM Helper plugin, and Airbus CERT’s COMIDA and Frank Boldewin’s COM Code Helper scripts are also useful options. Binary Ninja users can applyCOMpanionto make interface pointers and vtable calls easier to read. Recent Binary Ninja releases include COMpanion-related data rendering support. ComViewby malware and understanding interfaces together with functions present in their vtables. Tools such as ComView and OleView.NET allow researchers to inspect classes, interfaces, type libraries, proxy/stub information,DispatchLogger For dynamic analysis, tracing can help by observing COM activation and dispatch calls at runtime. DispatchLogger, written by Talos’ David Zimmer, is one example of a DLL that can be injected into a process to proxyDynamoRIOthe analysis environment to help with the mapping. Dynamic binary instrumentation frameworks such as DynamoRIO can also be used for runtime tracing of COM behaviors. IDA Prouse a plugin for your reverse-engineering tool that maps GUIDs to human-readable code. For example, in IDA Pro, the standard COM Helper can identify relevant class and interface IDs and rename locations in theOleView.NETunderstanding interfaces together with functions present in their vtables. Tools such as ComView and OleView.NET allow researchers to inspect classes, interfaces, type libraries, proxy/stub information, and methodTorkeylogging, clipboard capture, file collection and upload, process/window monitoring, persistence, Tor-based C2 communications, and GSM/GPRS device fingerprinting through AT commands. YARA A simplified YARA hunting rule for binaries that reference the Task Scheduler COM class and interface might look like: