Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Owner: User #71468
OperaMail DLL Hijack
Procmon screenshot:
MSIMG32.dll worked fine, as for other apps. One thing to note: the DLLDynamic Link Library stays loaded for the life of the process
\app\operamail\
Side Note: it looks for "operamail.dll" adjacent to itself, before properly finding it (\app\operamail\). The DLLDynamic Link Library exports only 6 functions, and may be easily reversed if needed later...