PlugX, a fully-featured remote access tool with a Chinese nexus, has been active in the wild for over a decade. However, a new variant was recently discovered to be using older, lesser-known Windows APIs via Component Object Model (COM) for staging and concealment - never-before-seen techniques. Leveraging an undesirable behavior in Windows Explorer, the malware uses COM to create folders that the Operating System cannot render or natively access, evading security scans that rely on the underlying Windows APIs. Additionally, this sucker is wormable, spreading across networks via USB air-gap jumping. Despite rapidly changing and improving security practices, old technology is still an effective means for malicious cyber activity. This presentation will describe how the threat actors used COM to instantiate Windows APIs and abuse Windows Explorer to remain undetected on their victim's machines. It will explain how and why COM is so often overlooked by security researchers and suggest further areas of research on the topic.