New attack uses MSC files and Windows XSS flaw to breach networks
ID: 5cdaa2ab-2843-5f1b-84b2-aa39cd79ee7e
STIX ID: report--5cdaa2ab-2843-5f1b-84b2-aa39cd79ee7e
Feed Name: Bleeping Computer
Elastic Security researchers uncovered 'GrimResource', a technique that delivers malicious Microsoft Management Console (.msc) files which exploit an unpatched DOM-based XSS in apds.dll to run JavaScript inside mmc.exe, reconstruct a VBScript using DotNetToJScript, load a .NET loader (PASTALOADER), and inject Cobalt Strike into dllhost.exe via DirtyCLR and process injection; a June 6, 2024 sample on VirusTotal shows active exploitation with no AV detections, and the report includes IOCs, YARA rules, and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
