CTIPilot

Lenovo PC Manager

product · product:lenovo-pc-manager single-source

Coverage timeline
1
first 2026-09-03 → last 2026-09-03
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
7
pinned v19.2 · see below

Hunting pivots

Releases covered
Lenovo PC Manager

ATT&CK techniques

7 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

T1055.012Process Injection: Process Hollowing×1

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×1

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Stealth TA0005

T1055.012Process Injection: Process Hollowing×1

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Credential Access TA0006

T1555.003Credentials from Password Stores: Credentials from Web Browsers×1

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · ATT&CK page ↗

Story timeline

  1. 2026-09-03MoiClient: an invoice-themed backdoor chains an RPC-based UAC bypass with a vulnerable Lenovo PC Manager driver to kill security products and steal browser credentials
    active-threatsA debug-object handle borrowed from winver.exe is enough to hijack a self-elevating system binary with no prompt

Where this entity is cited

  • active-threats1

Source distribution

  • asec.ahnlab.com1 (100%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Lenovo PC Manager (1)

2026-09-03 · view entry permalink →

NOTABLENATOB2

MoiClient: an invoice-themed backdoor chains an RPC-based UAC bypass with a vulnerable Lenovo PC Manager driver to kill security products and steal browser credentials

AhnLab's ASEC documents MoiClient (named for the "moimoi" string in its BYOVD component) distributed as a .vhdx file disguised as an invoice email attachment. The archive contains Invoice.Pdf.Exe, actually the legitimate SumatraPDF viewer, used to DLL-sideload a same-directory malicious uxtheme.dll, plus hidden support files (AhnLab ASEC, 2026-09-01). Execution moves into a legitimate process via classic process hollowing: MoiClient spawns explorer.exe suspended and overwrites its entry point with shellcode from a co-located data.dat. For privilege escalation, MoiClient connects over ncalrpc to the RPC interface of the AppInfo Service, launches winver.exe as a debug target to acquire a debug-object handle, then drives ComputerDefaults.exe (a system binary that auto-elevates) through the same RPC path, clones its process handle, and sets that cloned handle as the parent of subsequent sc.exe and PowerShell processes so they inherit elevated privileges with no UAC prompt shown (AhnLab ASEC, 2026-09-01). With elevated rights, MoiClient drops a vulnerable Lenovo PC Manager kernel driver, version 2.5.30.11281 of BootRepair.sys, under the name moimoi.sys in the %Public% path, registers it as a kernel service, and uses its device interface to pass process IDs of running security products for forced termination, targeting Windows Defender, Malwarebytes, Bitdefender, Kaspersky, Avast, AVG and McAfee by process name (AhnLab ASEC, 2026-09-01). A separate technique specifically neutralises Windows Defender: MoiClient downloads defendnot.dll and defendnot-loader.exe from its command-and-control server and runs them through the elevated PowerShell session. Persistence is a Task Scheduler job named MicrosoftWindowsUpdateTask<4-digit-number> (or the existing name with a trailing period appended on a collision) that fires every 30 minutes, re-launching the renamed SumatraPDF binary to re-trigger the DLL-sideload chain (AhnLab ASEC, 2026-09-01). The final payload, "MoiXD Stealer," runs in memory and uses a ChromeElevator-style technique to steal browser-stored passwords.

Triage: the RPC-based UAC bypass, cloning a process handle obtained through winver.exe as a debug target and attaching it as the parent of sc.exe or PowerShell, resembles a technique class Google Project Zero documented in 2019 against the AppInfo Service; a sc.exe or PowerShell process whose parent-process chain traces back through winver.exe or ComputerDefaults.exe rather than a normal interactive shell is not typical UAC-elevation behaviour and is the observable signature the mechanism supports.

MoiClient uses the ncalrpc protocol sequence to connect to the RPC interface of the AppInfo Service, then executes winver.Exe as a debug target and acquires the debug object handle.

version 2.5.30.11281 Of BootRepair.Sys (a vulnerable driver in Lenovo PC Manager) was exploited. MoiClient creates this driver in the %Public% Path under the name moimoi.Sys

The registered task runs every 30 minutes. At that time, SumatraPDF (named "demo.Exe") is launched, and "uxtheme.Dll," which is located in the same Path and is actually MoiClient, is reloaded.

AhnLab ASEC 2026-09-01
threat03 Sep 05:17Zsingle-sourceOpen finding ↗
Sources: AhnLab ASEC