logo

Hackers Exploit MSBuild LOLBin to Evade Detection in Fileless Windows Attacks

ID: e1502710-e615-57ab-b54c-28a54b36c1f9

STIX ID: report--e1502710-e615-57ab-b54c-28a54b36c1f9

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** The report details how attackers are repurposing MSBuild.exe as a LOLBin to execute inline C# project files for fileless payloads, evade signature-based defenses (including a PoC bypassing Windows Defender), and deliver PlugX via a phishing campaign using DLL sideloading; it concludes with detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.