APT28 SimpleLoader COM Hijack CLSID D9144DCD Registry Write

This rule detects the creation or modification of a COM object registry key under HKEY_CURRENT_USER\Software\Classes\CLSID\ with an 'InProcServer32' subkey. This is a common technique used by adversaries for persistence and privilege escalation by hijacking COM object references to execute arbitrary malicious code when the legitimate application attempts to use the hijacked COM object.