The article provides substantial new technical details about how malware families like Qakbot and WarmCookie exploit COM for lateral movement, persistence, and evasion, emphasizing the challenges of static analysis due to opaque GUIDs and indirect vtable calls.
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Talos | — |
Updated description with new technical details on how Qakbot and WarmCookie exploit COM, and added vendor and product information.
Initial creation