ThreatCluster

Registry Vulnerabilities in Windows Persistence Mechanisms

First seen 1 Jan 2026, 01:15 UTC Hexacorn 22

Article Content

Browse articles
ThreatCluster

Two Registry entries related to Microsoft Windows have been identified as potential persistence mechanisms for malicious activities. The entries HKLM\Software\Microsoft\MSDTC\XADLL and HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy\Test\AdmParseLibrary= are noted for their roles in loading DLL files and parsing template files, respectively.