logo

Hackers Abuse MSBuild LOLBin to Evade Detection and Launch Fileless Windows Attacks

ID: c461e436-870d-56bd-a16b-62ad78381be5

STIX ID: report--c461e436-870d-56bd-a16b-62ad78381be5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

This report describes attackers weaponizing the Microsoft-signed MSBuild.exe as a Living-Off-The-Land Binary to execute inline C# from .csproj files for fileless operations: a January 2025 reverse shell and a February 2026 campaign that used phishing, a downloader, and DLL sideloading (Avk.dll) to run malicious code while evading Windows Defender; defenders are advised to monitor MSBuild execution outside developer contexts, watch .csproj usage in temp/download folders, track MSBuild outbound connections, and detect sideloading behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.