Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
ID: 180a6b7f-b480-5b21-82f9-fe621395638a
STIX ID: report--180a6b7f-b480-5b21-82f9-fe621395638a
Feed Name: GBHackers
An active phishing campaign was observed delivering a five-layer, fileless loader that begins with a malicious JScript inside a TAR purchase-order lure, uses multiple runtime obfuscation layers and environment-variable staging to hide a Base64 .NET payload encoded as CJK/Hanzi characters, and reflectively loads the assembly in memory. The report details techniques that evade AMSI and disk forensics, provides MITRE ATT&CK mappings and hunting pivots (e.g., wscript.exe -> conhost.exe –headless powershell.exe, scriptblocks created from environment variables, large sets of randomized environment variables, and reflective .NET loading), and associates the final-stage payload with Agent Tesla while warning the loader could deliver a range of follow-on malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
