App Review Comodo Internet Security vs targeted ransomware attack.

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
me
However, the attack presented in the video was easily detected by Microsoft Defender (I did not submit the DLL to analysis).
...
That is why the attackers avoid this method in the wild. They use other attack vectors optimized to bypass popular AVs.

I tried Bitdefender Total Security. It blocked the attack behaviorally.(y)

1771978018199.png


The attack was successful when Advanced Threat Defense was disabled.
 
Last edited:
But the ultimate result is blocking the attack post-execution by both.

Microsoft Defender detected the DLL on the pre-execution level. Bitdefender did not detect the DLL, but it did detect the abused EXE's actions upon execution.
 
Microsoft Defender can block the attack on execution via the ASR rule:

Event[0]:
Time Created : 25/02/2026 13:42:48
ProviderName : Microsoft-Windows-Windows Defender
Id : 1121
Message : Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: c0033c00-d16d-4114-a5a0-dc9b3a7d2ceb
ConfigureDefender option: Block use of copied or impersonated system tools
Detection time: 2026-02-25T12:42:48.415Z
User: ahome\andrzej
Path: E:\H_C\DLL\ComodoBypassAAABBB\OPEN_ME.EXE
Process Name: C:\Windows\explorer.exe
Target Commandline:
Parent Commandline: C:\WINDOWS\Explorer.EXE
Involved File:
Inheritance Flags: 0x00000000
Security intelligence Version: 1.445.242.0
Engine Version: 1.1.26010.1
 
However, we both agree that Comodo nails at home, if one can live with @cruelsister's settings.:)
Overall, Comodo is effective for home users, regardless of configuration, except for those involved with cracks, keygens, and mods. I doubt the upcoming version will address any issues related to trusted malware or services; if I recall correctly, Xcitium offers solutions for these through the console or profile.
 
Here is a similar example in the wild (InfoStealer), although it also uses shell code. It would be interesting to test it against Comodo to see how strong Comodo's shell code injection protection is.
https://thehackernews.com/2026/03/sloppylemming-targets-pakistan-and.html?m=1
https://malwaretips.com/threads/slo...using-dual-malware-chains.140014/post-1173685

1772534784527.png


There is a difference compared to my video. In the case of video, the targets were machines with Comodo protection. The in-the-wild example had probably a more general purpose, although it was still a targeted attack against government entities and critical infrastructure operators in some countries (not against home users). Home users are safe (so far).

There is also a second infection chain in the article (Excel VBA Macro + DLL hijacking = keylogger). This one also has great chances to bypass Comodo.
 
Last edited:
It is very hard to find an in-the-wild attack that could bypass Comodo. Probably impossible against home users.
However, here is a recent example (targeted attack on government entities) that uses twice the method presented in my video:

1784647286354.png

The EXE files are benign/legitimate, so most AVs can also fail to detect the attack (as 0-day).
One of the used DLLs is still undetected by such strong AVs as Bitdefender, CrowdStrike Falcon, Elastic, GData, Eset, Emsisoft, Palo Alto Networks, TrendMicro, Xcitium, ZoneAlarm.
From VirusTotal, it follows that Xcitium did not detect any of the DLLs noted in the article, but it has an option to block unrecognized DLLs, which can block such attacks anyway.
If the attack accidentally happened at home, it could be blocked by SAC (DLLs are unsigned).
 
Last edited:
  • +Reputation
Reactions: Khushal
It is very hard to find an in-the-wild attack that could bypass Comodo. Probably impossible against home users.
However, here is a recent example (targeted attack on government entities) that uses twice the method presented in my video:

View attachment 298951
The EXE files are benign/legitimate, so most AVs can also fail to detect the attack (as 0-day).
One of the used DLLs is still undetected by such strong AVs as Bitdefender, CrowdStrike Falcon, Elastic, GData, Eset, Emsisoft, Palo Alto Networks, TrendMicro, Xcitium, ZoneAlarm.
From VirusTotal, it follows that Xcitium did not detect any of the DLLs noted in the article, but it has an option to block unrecognized DLLs, which can block such attacks anyway.
If the attack accidentally happened at home, it could be blocked by SAC (DLLs are unsigned).
Does this defense lead us to believe Comodo will protect where others won't or would that be a misrepresentation of Comodo's abilities
 
  • Like
Reactions: Khushal
Does this defense lead us to believe Comodo will protect where others won't or would that be a misrepresentation of Comodo's abilities

There is no effective defence from Comodo against such attacks, due to poor detection of DLLs. This attack is still undetected by Comodo on VirusTotal after two weeks. One of the DLLs used in the attack has been undetected for 5 months. However, Comodo is intended for home use where such attacks are nonexistent, and it will indeed protect where others won't. That is why Comodo users can still consider it a good solution at home (so far).
Most AVs can also fail when this kind of malware is 0-day old, but will better protect afterwards.
 
Last edited:
This thread is a kind of challenge for the following:
  1. Comodo protection can be bypassed, but in the wild, this can happen only in highly targeted attacks.
  2. Comodo has a few unpatched exploits, but no one bothers to exploit Comodo in the wild.
  3. Comodo Internet Security (Comodo Firewall) is rather poorly supported, but this has no visible impact on its security at home.
  4. Comodo has rather poor detection, but it does not affect the overall protection at home due to sandboxing unrecognized files and strong script blocking.
So far, Comodo wins the challenge. We will see how long.
 
  • Like
Reactions: Jonny Quest