Hackers Abuse MSBuild LOLBin to Evade Detection and Launch Fileless Windows Attacks
ID: c461e436-870d-56bd-a16b-62ad78381be5
STIX ID: report--c461e436-870d-56bd-a16b-62ad78381be5
Feed Name: cybersecurityNews.com
This report describes attackers weaponizing the Microsoft-signed MSBuild.exe as a Living-Off-The-Land Binary to execute inline C# from .csproj files for fileless operations: a January 2025 reverse shell and a February 2026 campaign that used phishing, a downloader, and DLL sideloading (Avk.dll) to run malicious code while evading Windows Defender; defenders are advised to monitor MSBuild execution outside developer contexts, watch .csproj usage in temp/download folders, track MSBuild outbound connections, and detect sideloading behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
