Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CrowdStrike researchers have documented active threat actor abuse of Microsoft’s ClickOnce deployment framework, a legitimate Windows application delivery mechanism, to install malware, maintain persistent access, and receive covert updates, all without elevated privileges or triggering most endpoint security tools. Attackers exploit the trusted process trees of dfsvc.exe and rundll32.exe alongside file types (.application, .appref-ms) that most security tools treat as benign, creating a detection gap that persists even in well-defended environments. Organizations running Windows across any version are exposed; the primary business risk is undetected, long-term attacker presence on corporate endpoints.

Author

Tech Jacks Solutions