TGViewer
Proxy Bar Proxy Bar @proxy_bar · 21.5K subscribers
Post #3316 6.83K
COMouflage: Stealthy DLL Surrogate Injection for Process Tree Evasion

Original text by S12 – 0x12Dark Development

The article introduces COMouflage, a stealthy Windows process-injection technique that abuses the legitimate COM DLL Surrogate mechanism to execute malicious code inside trusted system processes. Instead of directly injecting into a target process, the attacker registers a fake COM object in the Windows registry under HKEY_CURRENT_USER, which does…

https://core-jmp.org/2026/04/comouflage-stealthy-dll-surrogate-injection-for-process-tree-evasion/
  • 😱 8
  • 🔥 1
More from @proxy_bar
  1. Sep 28, 2026CVE-2026-19444: kubectl 😆😆😆
  2. Sep 28, 2026Prompt Injection in the Wild
  3. Sep 24, 2026Вспомнилось ! Был такой хороший гайд Introduction to Exploit Development Сегодня он интере…
  4. Sep 23, 2026Linux container escape * PoC
  5. Sep 21, 2026Идея для "быстрых свиданий" Ну это те, которые 5 минут общаешься, потом пересаживаетесь. З…
  6. Sep 20, 2026А скиньте фотки с тусы а )))
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →