logo

GrimResource - Microsoft Management Console for initial access and evasion

ID: 23a429db-02fd-5af3-8c3f-316d17762d23

STIX ID: report--23a429db-02fd-5af3-8c3f-316d17762d23

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2024-06-22

Date Updated: 2026-04-27

...
...

Elastic Security researchers describe 'GrimResource', a novel technique that leverages an XSS issue in apds.dll via crafted MSC files to execute arbitrary JavaScript in mmc.exe, chain into DotNetToJScript and a PASTALOADER .NET loader, and ultimately deploy a Cobalt Strike payload; the report includes behavioral detections (EQL), a YARA rule, and observable hashes for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.