logo

Abusing Trusted Applications with Nested Execution

ID: adf527d8-9fad-54fd-9aac-919061db368b

STIX ID: report--adf527d8-9fad-54fd-9aac-919061db368b

Feed Name: Huntress Blog

Threat Score
55/100

Date Published: 2017-10-02

Date Updated: 2026-04-28

...
...

Huntress investigators found multiple Windows services invoking the same executable (WseClientSvc.exe). By reversing the binary they discovered it attempts to load a .NET assembly passed as an argument; building a simple passthrough .NET module allowed them to use the signed Microsoft binary to execute arbitrary code (demonstrated with calc.exe), illustrating a living-off-the-land code execution technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.