INTEL_REPORT
Cisco Talos Blog · published 6/25/2026, 10:00:26 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Introduction to COM usage by Windows threats Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors. Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation&#x…
https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threats
sha256:2c79c23b609249a0cb103d3d1d6364691ec7cc6d134436f0dc9bf679ceac5c03
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| combase.dll |
| Open → |
| domain | shell.application | Open → |
| domain | excel.application | Open → |
| domain | msxml2.xmlhttp | Open → |
| domain | winhttp.winhttprequest | Open → |
| domain | itaskservice.connect | Open → |
| domain | iwbemlocatorvtbl.connectserver | Open → |
| domain | clsid.cfg | Open → |