Hackers Exploit MSBuild LOLBin to Evade Detection in Fileless Windows Attacks
ID: e1502710-e615-57ab-b54c-28a54b36c1f9
STIX ID: report--e1502710-e615-57ab-b54c-28a54b36c1f9
Feed Name: GBHackers
Threat Score
**Executive summary:** The report details how attackers are repurposing MSBuild.exe as a LOLBin to execute inline C# project files for fileless payloads, evade signature-based defenses (including a PoC bypassing Windows Defender), and deliver PlugX via a phishing campaign using DLL sideloading; it concludes with detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
