Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Attackers are abusing Microsoft’s ClickOnce application deployment framework to install malware, maintain persistence, and silently update payloads on Windows endpoints, all without administrator privileges. The attack chain runs entirely through trusted Microsoft processes (dfsvc.exe, rundll32.exe), making it largely invisible to mail gateways and traditional endpoint controls that do not inspect .application and .appref-ms file types. Any organization running Windows endpoints where ClickOnce deployments are permitted is exposed, and the built-in auto-update mechanism means a single successful delivery can sustain a long-term, evolving foothold.

Author

Tech Jacks Solutions