# T1546.015 Component Object Model Hijacking

> As of 2026-10-05, T1546.015 (Component Object Model Hijacking) appears in 15 tracked threats, first reported 2026-02-04 and most recently 2026-09-29, with linked actors including APT-C-60, Head Mare, APT10; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 15 (4 critical, 10 high, 1 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-09-29
- **Threat actors:** 28
- **Detection rules:** 51 (counts only; Blue tier and above)

## Key facts

- **ID:** T1546.015
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1546
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1546/015/

## Activity timeline

T1546.015 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1546.015 Component Object Model Hijacking is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1546 Event Triggered Execution](https://intel.threadlinqs.com/technique/T1546). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 4 critical, 10 high, 1 medium.

Threats that use T1546.015 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (10 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (9 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (8 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (8 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

28 tracked threat actors appear in the threats that use T1546.015; the most frequent are [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) (2), [Head Mare](https://intel.threadlinqs.com/actor/Head%20Mare) (2), [APT10](https://intel.threadlinqs.com/actor/APT10) (1), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT32](https://intel.threadlinqs.com/actor/APT32) (1).

## Data sources

Telemetry that can reveal T1546.015, per MITRE ATT&CK.

- Command — Command Execution
- Module — Module Load
- Process — Process Creation
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 2
- [Head Mare](https://intel.threadlinqs.com/actor/Head%20Mare) — 2
- [APT10](https://intel.threadlinqs.com/actor/APT10) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1
- [GreyVibe](https://intel.threadlinqs.com/actor/GreyVibe) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1

## Tracked threats

15 tracked threats use T1546.015.

- [CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user…](https://intel.threadlinqs.com/threat/TL-2026-2786) — high — 2026-09-29
- [APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malware](https://intel.threadlinqs.com/threat/TL-2026-2134) — high — 2026-08-24
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoors](https://intel.threadlinqs.com/threat/TL-2026-1982) — critical — 2026-08-11
- [CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign](https://intel.threadlinqs.com/threat/TL-2026-2765) — high — 2026-07-31
- [LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…](https://intel.threadlinqs.com/threat/TL-2026-1449) — high — 2026-07-17
- [LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…](https://intel.threadlinqs.com/threat/TL-2026-1373) — high — 2026-07-15
- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-1287) — medium — 2026-07-14
- [SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…](https://intel.threadlinqs.com/threat/TL-2026-1284) — high — 2026-07-13
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as…](https://intel.threadlinqs.com/threat/TL-2026-1088) — high — 2026-07-02
- [Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…](https://intel.threadlinqs.com/threat/TL-2026-0755) — high — 2026-06-10
- [OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relay](https://intel.threadlinqs.com/threat/TL-2026-0480) — high — 2026-05-07
- [CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…](https://intel.threadlinqs.com/threat/TL-2026-0347) — critical — 2026-04-10
- [Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy…](https://intel.threadlinqs.com/threat/TL-2026-0137) — high — 2026-02-24
- [RomCom & Paper Werewolf Exploiting WinRAR CVE-2025-8088 Zero-Day via ADS Path Traversal](https://intel.threadlinqs.com/threat/TL-2026-0090) — critical — 2026-02-04

## Related CVEs

CVEs referenced by the tracked threats that use T1546.015, most frequent first.

- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-50610](https://intel.threadlinqs.com/cve/CVE-2026-50610)
- [CVE-2026-72529](https://intel.threadlinqs.com/cve/CVE-2026-72529)

## Detection coverage

Threadlinqs maintains 51 detection rules mapped to T1546.015 (SPL 22, KQL 18, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

51 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1546 Event Triggered Execution](https://intel.threadlinqs.com/technique/T1546) — 145 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1546.015
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
