logo

LOLBins – Analyzing attack techniques with MSBuild

ID: 12df04b1-d5e7-50a0-96e0-78bb28020b69

STIX ID: report--12df04b1-d5e7-50a0-96e0-78bb28020b69

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-26

Author: ATCP

...
...

MSBuild.exe is being abused as a LOLBins vector to run inline C# code and to download and execute payloads (including DLL sideloading and reverse shells). The report validates a Defender-bypass technique and describes a February 2026 phishing campaign that disguises a signed MSBuild executable and a malicious .csproj to fetch and execute additional files; it includes MD5 indicators and C2 URLs and recommends behavior- and context-based detections (process context, project file execution, network patterns, and DLL load analysis).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.