logo

Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload

ID: 180a6b7f-b480-5b21-82f9-fe621395638a

STIX ID: report--180a6b7f-b480-5b21-82f9-fe621395638a

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-17

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

An active phishing campaign was observed delivering a five-layer, fileless loader that begins with a malicious JScript inside a TAR purchase-order lure, uses multiple runtime obfuscation layers and environment-variable staging to hide a Base64 .NET payload encoded as CJK/Hanzi characters, and reflectively loads the assembly in memory. The report details techniques that evade AMSI and disk forensics, provides MITRE ATT&CK mappings and hunting pivots (e.g., wscript.exe -> conhost.exe –headless powershell.exe, scriptblocks created from environment variables, large sets of randomized environment variables, and reflective .NET loading), and associates the final-stage payload with Agent Tesla while warning the loader could deliver a range of follow-on malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.