logo

New attack uses MSC files and Windows XSS flaw to breach networks

ID: 5cdaa2ab-2843-5f1b-84b2-aa39cd79ee7e

STIX ID: report--5cdaa2ab-2843-5f1b-84b2-aa39cd79ee7e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Elastic Security researchers uncovered 'GrimResource', a technique that delivers malicious Microsoft Management Console (.msc) files which exploit an unpatched DOM-based XSS in apds.dll to run JavaScript inside mmc.exe, reconstruct a VBScript using DotNetToJScript, load a .NET loader (PASTALOADER), and inject Cobalt Strike into dllhost.exe via DirtyCLR and process injection; a June 6, 2024 sample on VirusTotal shows active exploitation with no AV detections, and the report includes IOCs, YARA rules, and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.