In my previous post I described a persistence mechanism that is triggered when someone is connecting to the infected system via RDP.
This is an interesting way to stay alive, but it would be probably much better if we could apply the same logic not to the server, but to the client.
That is – launch a DLL of our choice anytime someone tries to use mstsc.exe…
Did I mention testing?
Yet another artifact that seems to be testing-related is this:
- HKLM\SOFTWARE\Microsoft\Terminal Server Client
ClxDllPath=<path to DLL>
Adding this to the Windows 10 Registry:
will give us the following result:
We don’t even need to connect to the real system. Just launching mstsc.exe is enough,