Rare retention techniques

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Rare persistence techniques
In the first six months of 2026, the PT ESC IR team recorded a number of rare persistence techniques on compromised hosts, which we will discuss in upcoming posts.
1️⃣ Zabbix Agent
Zabbix Agent is a lightweight service that collects metrics from a host and transmits them to a server, routinely used by administrators.
The essence of the attackers’ persistence technique (for example, the PhantomCore group) boils down to turning the legitimate agent into a hidden backdoor. They deliver their own installer (zabbix.msi) to the host and replace the server address in the configuration file with a C2 under their control.
Key configuration fields for the attack:
• Server= and ServerActive= specify the IP or domain of the C2 server for passive and active checks;
• Hostname= serves as the victim’s unique identifier in the C2 panel;
• ListenPort= reassigns the port (default 10050) to avoid a conflict with the native agent;
• UserParameter= is the key element, allowing arbitrary OS commands to be registered as Zabbix metrics;
• AllowKey=system.run[*] permits direct command execution.
The control channel operates over the native Zabbix protocol (JSON over TCP/TLS), masking malicious traffic as legitimate monitoring and allowing agents in active mode to “call back” to the C2 on their own. During post-exploitation, the attacker, through the graphical interface of the Zabbix server, centrally gains access to files and processes and the ability to silently deliver and launch additional scripts on the compromised host.
Main indicators of compromise: sudden outbound connections with non-standard monitoring ports (10050/10051) to external IP addresses and the presence of shell invocations (cmd, sh, powershell) in the agent’s configuration file.
2️⃣ TimeProvider
The attackers used a rare persistence technique via the TimeProvider mechanism (Windows time provider), corresponding to the MITRE ATT&CK T1543.003 tactic.
The essence of the method is that the Windows Time service (W32Time) automatically loads all libraries registered in the registry key on every system startup: HKLM\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders
The attackers created their own provider in this key: in the DllName parameter they specified the path to a malicious DLL, and set the Enabled parameter to 1. After the OS reboots, the W32Time service loads the specified library in the context of the svchost.exe process with Local System privileges, which ensures stealthy and reliable persistence in the system.
Requirements for the DLL: to load successfully, it must export the TimeProvOpen() function (screenshot 1), which W32Time calls when initializing the provider. This function serves as the entry point and is usually used by attackers to launch the main payload.
To be continued tomorrow (in the following posts) 🔽
#ir #tips #dfir
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



