Recent research shows attackers continue to rely on legitimate Windows administration features for lateral movement, with WMI, Scheduled Tasks, SMB admin shares, RDP, PsExec, and anomalous Kerberos activity remaining common across enterprise intrusions. VMware telemetry covering 489 multi-host intrusions found 44.7% included lateral movement, typically across fewer than 20 hosts and using short, focused paths, while Gigamon detailed how remote WMI execution and Scheduled Tasks often blend into normal administration through DCE/RPC operations such as ExecMethod, SchRpcRegisterTask, SchRpcRun, and SchRpcDelete, frequently paired with SMB payload transfer and shared outbound command-and-control destinations.
Newer Windows tradecraft is also exploiting cross-session activation and service manipulation to execute code under another user’s interactive session or persist more stealthily after compromise. Purple Team research described COM/DCOM abuse using RunAs=Interactive User, remote registry changes, and CLSID hijacking—including abuse of SpeechRuntime.exe via the CLSID {655D9BF9-3876-43D0-B6E8-C83C1224154C}—as well as tooling such as COMThanasia, PermissionHunter, SessionHop, and SpeechRuntimeMove; separate analysis showed attackers can evade simpler detections by abusing Windows Service recovery functions and registry-backed service creation. Across these techniques, defenders are urged to correlate process creation, registry access, service state changes, authentication context, and network telemetry, with attention to Windows events including 4688, 4663, 4657, 7036, and 7040.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
VMware's quantitative analysis used a 30-day telemetry dataset from VMware Contexa and NSX customers that began on April 1, 2022. This dataset later underpinned findings on how often lateral movement appeared in multi-host intrusions.
Purple Team reports that Grimur Grimursson discussed abuse of Windows service recovery functions and released the RecoverIt tool. The proof of concept showed how a service crash can be configured to execute an arbitrary command.
Purple Team says Grzegorz Tworek disclosed that Security Descriptor Definition Language can be abused to alter Windows service permissions. This enables lower-privileged users to create or modify services in ways useful for adversary activity.
Purple Team states that Andrew Oliveau released SessionHop, a proof of concept that uses IHxHelpPaneServer to hijack specified user sessions locally. The tool creates a session moniker and invokes Execute() to run arbitrary files in another user's session.
Michael Zhmaylo released a proof of concept that creates the IHxHelpPaneServer COM object in another user's session and invokes Execute() to run code. The release demonstrated practical Cross-Session Activation abuse of COM/DCOM for lateral movement.
Purple Team reports that Michael Zhmaylo released COMThanasia, including PermissionHunter for enumerating COM objects and their launch and activation permissions. The tooling is presented as supporting Cross-Session Activation candidate discovery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
ipurple.team
Open sourceipurple.team
Open sourceipurple.team
Open sourceblogs.vmware.com
Open sourceblog.gigamon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.