#PowerShell-based
A Lunex-linked attack chain targets Ukrainian users, using a false CAPTCHA, BYOVD to disable kernel monitoring, and a browser-based PowerShell C2 agent for data and crypto theft with persistence.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 25, 2026 at 3:15 PM
A Lunex-linked attack chain targets Ukrainian users, using a false CAPTCHA, BYOVD to disable kernel monitoring, and a browser-based PowerShell C2 agent for data and crypto theft with persistence.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 25, 2026 at 3:15 PM
A Lunex-linked attack chain targets Ukrainian users, using a false CAPTCHA, BYOVD to disable kernel monitoring, and a browser-based PowerShell C2 agent for data and crypto theft with persistence.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 25, 2026 at 3:13 PM
CERT-AGID disrupted a MintsLoader campaign abusing compromised PEC mailboxes to send fake payment reminders, pushing ZIP attachments that launched RATs and stealers. #MintsLoader #PEC #CERTAGID
MintsLoader Via PEC: False Payment Reminders To Spread Malware
CERT-AGID identified and disrupted a new MintsLoader campaign that abused compromised PEC mailboxes to send convincing fake invoice-payment messages to other certified email addresses. The attack chain delivered a ZIP file containing HTML, JavaScript, PowerShell, and MintsLoader components, with rotating infrastructure and DGA-based domains leading to final payloads such as RATs and stealers. #CERT-AGID #MintsLoader #PEC
www.hendryadrian.com
September 25, 2026 at 6:45 AM
AI-generated · Microsoft DSC 3.3.0 is GA with list-based Windows resources and wider --what-if coverage. Test firewall ownership and Registry adapter limits before a maintenance window. https://devblogs.microsoft.com/powershell/announcing-dsc-v3-3-0/
What should you validate before using Microsoft DSC 3.3.0 in a maintenance window?
Microsoft Desired State Configuration 3.3.0 is generally available, with new built-in Windows resources and wider `--what-if` coverage for services, firewall rule lists, and SSHD configuration. Before a maintenance window, validate firewall ownership, registry type coverage, command aliases, and the experimental status of synthetic export filtering.
kira-ai.de
September 24, 2026 at 2:40 PM
Huntress traced an INC ransomware incident across 175+ endpoints, finding early persistence, RDP lateral movement, obfuscated PowerShell, AnyDesk delivery, and BYOVD driver abuse that disabled defenses. #INC #AnyDesk #Impacket
The Tale Of Two INC Ransom Notes: A Ransomware Timeline | Huntress
Huntress investigated an August post-incident case involving INC ransomware that impacted at least 175 endpoints, with traces found on domain controllers and evidence of early persistence, lateral movement, and later ransomware deployment. Researchers also uncovered two ransom notes, an AnyDesk-based deployment path, and a BYOVD technique used to load a driver and disable security tools. #INC #AnyDesk #Impacket #HwAudio #HWAuidoOs2Ec.sys
www.hendryadrian.com
September 23, 2026 at 8:30 PM
STOMP Backdoor Uses PowerShell for Sensitive Data Theft #ClipboardStealing #CommandAndControl #DataTheft
STOMP Backdoor Uses PowerShell for Sensitive Data Theft
An advanced malware campaign known as TASK#STOMP has recently been discovered, which utilizes a PowerShell-based backdoor to collect business documents, Wi-Fi passwords, clipboard data, and screenshots from compromised computers using a PowerShell backdoor. Moreover, the malware also provides attackers with remote command execution and maintains multiple channels for further access. VBScript files are executed via the legitimate Windows Script Host utility wscript.exe in order to initiate the infection.  In spite of the fact that the exact method of delivery has not been confirmed, phishing or social engineering could be considered possible methods of delivering the script. Following the script's delivery, it sets up a set of scheduled tasks resembling legitimate Windows components, establishing persistence.  By naming these tasks Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler, malicious activities can be blended seamlessly with normal system activities. Another persistence mechanism places another VBScript file in the Windows Startup folder, enabling it to run when the user logs in.  Upon launching the malware, it executes two PowerShell components. Among these are sys_loader.ps1, which collects documents, gathers system information, steals Wi-Fi passwords, monitors clipboards, captures screenshots, and executes remote commands. Another persistent command-and-control channel, win_conn.ps1, provides additional collection capability as well as a persistent command-and-control channel.  By monitoring each other and restarting the other process if one is disabled, this setup provides redundancy, making it more difficult to remove the malware if only one process is terminated or a single persistence entry is deleted. In addition to hiding execution activities, timestamp manipulations, and cleanup activities, Task#STOMP can also be used for continuous document theft, increasing the difficulty of detection and forensic investigation.  As opposed to collecting only files that are already present on an infected computer, TASK#STOMP monitors the file system for newly created or modified documents. This enables the collection of business files as they appear and change during an active infection. In addition to obtaining Wi-Fi credentials and clipboard contents, the malware targets saved Wi-Fi credentials as well.  With clipboard monitoring, operators can identify information temporarily copied by users, while screenshot capture allows them to view information displayed on a compromised system. By combining these capabilities with remote command execution, Task#STOMP is able to gather more information about user activity than a conventional file-stealing malware.  A separate command-and-control path, Win_conn.ps1, is maintained by TASK#STOMP in addition to data collection. From win_conn_cfg.dat, the component decodes its configuration and connects to attacker-controlled infrastructure at corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz. Researcher identification of related traffic can be improved by using a hardcoded authentication token for communication.  Parts of network communication are handled by a compiled C# component. During connection times, connections can proceed when certificates are invalid, self-signed, or otherwise mismatched due to the code disabling TLS certificate validation. This reduces the level of protection usually provided by certificate checks and makes it easier for the malware to communicate with its servers. Additionally, TASK#STOMP alters file timestamps and cleans up activity following execution to provide further anti-forensic measures.  According to the researchers, several files have been backdated to January 15, 2024, but that date is not conclusive of when the campaign began. This date was deliberately inserted by the malware, and therefore cannot be regarded as evidence of the age of the campaign. Securonix has not determined why the malware opens a page associated with irantenders[.]com in Chrome, but the page relates to government contracts and tenders in Iran.  Securonix has not established whether the site indicates a specific victim profile or why it is opened. Researchers have cautioned that the domain alone may not be sufficient to confirm the campaign's geographical or sectoral targeting. Securonix has not linked TASK#STOMP to a known threat group. Due to the use of a single compromised system, it is unclear how the overall campaign scope and duration were determined.  The initial delivery method is also unclear, although similar VBScript campaigns suggest phishing involving archive or disk image attachments as a possible route. To detect an infection, researchers recommend examining suspicious Windows Script Host and PowerShell activity that originates from writable locations, newly created scheduled tasks, and instances where PowerShell invokes the C# compiler from .NET C#.  A suspected infection can be investigated with additional evidence from PowerShell Script Block Logging, AMSI telemetry, and scheduled task records.
dlvr.it
September 22, 2026 at 3:01 PM
PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner gbhackers.com/powershell-m...
PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
A sophisticated cryptomining campaign is employing multiple layers of obfuscation to conceal malicious PowerShell payloads and ultimately deploy an XMRig-based cryptocurrency miner.
gbhackers.com
September 20, 2026 at 10:46 AM
Learning #PowerShell syntax is the easy part. The *Why* of PowerShell maybe isn't so obvious. That's why I wrote Behind the PowerShell Pipeline based on my 20 years of PowerShell experience. Learn what you didn't know you needed to know.
September 19, 2026 at 11:18 PM
Multi-stage intrusion used Registry-stored PowerShell, DNS TXT records, PNG and WAV payloads, and in-memory .NET loading to deploy XMRig mining while weakening Defender and PowerShell logging. #XMRig #RegistryHiding #InMemoryLoad
From Registry-Stored PowerShell To In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain
Researchers analyzed a multi-stage infection that used Registry-stored PowerShell, DNS TXT records, PNG and WAV file payload containers, and in-memory .NET loading to hide its activity. The chain ultimately deployed an XMRig-based cryptocurrency miner while maintaining a separate C2 channel and weakening Microsoft Defender and PowerShell logging controls. #XMRig #WinRing0.sys #RealtekHDAudio.wav #sslvalidcert.com #httptls.org
www.hendryadrian.com
September 18, 2026 at 7:45 AM
Based on a community tip (we love those!), we discovered yet another malware family that's bringing its own Python interpreter—and a few other tricks.

Bring-Your-Own-Python is *so hot right now*

ifin.network/t/quick...

#ThreatIntel #ThreatIntelligence #IFIN
QuickFix: Yet Another Bring-Your-Own-Python Payload
Last Updated: 2026-09-16T14:53:57Z (UTC) What’s Happening TL;DR: `fileupdates.blob.core.windows[.]net is hosting “QuickFix,”, a new-ish installer file with PowerShell that installs its own Python interpreter, then activates a light C2 beacon for Python commands send via JSON. The detection opportunity is Python executing outside of expected directories. This was a tip from Fedi and turned into a really fun investigation. The tipper was surprised that Microsoft even allowed that blob storage...
ifin.network
September 16, 2026 at 3:49 PM
[IMP Post] 📌Complete Guide to Intune Win32 App Requirement Rules using Built-In and PowerShell-Based Conditions - www.anoopcnair.com/intune-win32...
#MSIntune #Win32Apps #PowerShell #DeviceManagement #HTMDCommunity
September 14, 2026 at 9:45 AM
AsyncRAT Hides in charmap.exe: How a Commodity RAT Mastered the Art of Evasion
AsyncRAT Hides in charmap.exe: How a Commodity RAT Mastered the Art of Evasion
A five-stage AsyncRAT campaign abuses AutoIt and PowerShell to inject its payload into charmap.exe, bypassing traditional file-based detection. The key is tracking behavioral chains, not static artifacts.
deafnews.it
September 14, 2026 at 8:16 AM
Part 23 taught me to separate:

command observed

from

action confirmed.

That distinction keeps an investigation evidence based.

Part 24: following the parent and child process relationships around PowerShell.
September 12, 2026 at 11:01 AM
Noted.

The -WhatIf scenario should be considerably better with a PowerShell based harness, since -WhatIf is built into the language.

Commands can SupportShouldProcess for explicit confirmation, and -WhatIf will either output text about what would write confirmation or output objects.
September 11, 2026 at 10:49 PM
Fun little side project based on some shell code I wrote last year: one file that is valid bash AND PowerShell at the same time. Runs on almost any OS. Replaces curl|bash with an added integrity check.

github.com/remcovanmook...
GitHub - remcovanmook/hexec: Four HTTP tools - hget, hexec, hwait, hmirror - in bash, zsh, ash and PowerShell, using only what the environment already ships. No curl, no wget.
Four HTTP tools - hget, hexec, hwait, hmirror - in bash, zsh, ash and PowerShell, using only what the environment already ships. No curl, no wget. - remcovanmook/hexec
github.com
September 11, 2026 at 2:25 PM
Microsoft blocks EWS in Exchange Online on Oct 1
Something in your tenant is probably still using it, a backup tool, a sync script.

If you don't build the AppID allow-list, Microsoft builds one for you, but might miss important apps

Two PowerShell scripts to help you: lazyadmin.nl/office-365/e...
EWS is Being Blocked in Exchange Online - How to Find every App still Using it
Exchange Online starts enforcing an AppID-based EWS allow-list on October 1, 2026. Learn how EWSEnabled and EWSAllowedAppIDs work, and how to find every app still calling EWS before Microsoft decides ...
lazyadmin.nl
September 10, 2026 at 9:07 AM
I believe you might be generalizing based off of bash / Windows batch.

PowerShell has about every bell and whistle you'd ever need in a programming language. Includes objects and strong typing (when you need it).

It was literally designed for production at scale.
September 8, 2026 at 5:38 PM
shipping a browser-based powershell-to-exe builder that skips the heavyweight toolchain is such a clean first cut — the “core is live, still improving” framing is exactly how people actually try a tool.
September 6, 2026 at 12:45 AM
I’ve been working on a new project called EXEscript, a browser-based PowerShell to EXE builder for Windows.

Build portable executables from PowerShell scripts without setting up a heavyweight development environment.

Try it: exescript.com

Still improving it, but the core builder is live now.
EXEscript - PowerShell to EXE
Turn PowerShell scripts into portable Windows EXE files with configurable architecture, window mode, runtime, UAC, and app options.
exescript.com
September 6, 2026 at 12:38 AM
SANS StormCast Highlights PowerShell Scripts for Azure AD Security, Critical Keycloak Vulnerability, and LLM Bypass Techniques
The August 21, 2026, SANS Internet Storm Center StormCast, presented by Johannes Ullrich from Jacksonville, Florida, highlighted two PowerShell scripts for Microsoft Graph automation to manage Entra (Azure AD) security. The first script identifies stale user accounts—those inactive for extended periods—and lists their assigned licenses, while the second collects users flagged by Entra’s risk detection system, detailing reasons like unusual browsers, geographic origins, or ASN-based anomalies. Keycloak version 26.7.2 was released to fix a critical password reset vulnerability allowing unauthenticated attackers to spoof verification tokens and reset any user’s password without email access. A blog post demonstrated 'cryptographic context injection,' a technique to bypass LLM guardrails by encrypting malicious requests, decrypting them only after the initial security filter. N-able’s Passportal password manager was patched for a cross-origin messaging flaw where improper origin checks enabled any website to extract stored passwords, posing a severe risk to managed service providers. The vulnerabilities underscore the importance of input validation after data transformation and secure cross-window communication in browser extensions.
www.cyberhub.blog
September 5, 2026 at 8:37 PM
TerminalFix used a fake CAPTCHA to inject a reverse tunnel.

Microsoft identified the TerminalFix campaign leveraging a fake Cloudflare CAPTCHA to deploy a PowerShell that installs a TLS/WebSocket reverse tunnel using steganography and signed binaries. This bypasses…

Read more on Kimbodo:
How to Detect and Stop Stealth Reverse‑Tunnel Intrusions — Lessons from the TerminalFix Campaign
What Happened Microsoft observed a multistage intrusion campaign (TerminalFix / ClickFix variant) that combined social engineering, signed‑binary abuse, steganography and a Python‑based reverse tunnel to enable silent pivoting and reconnaissance…
kimbodo.com
September 5, 2026 at 8:24 PM
The interesting part isn't the CAPTCHA disguise, it's the shift to reverse tunnels. TerminalFix makes the malicious connection look like normal outbound traffic. Defenders need to watch for unexpected PowerShell or Terminal invocations, not just browser-based attacks.

#CyberSecurity
September 5, 2026 at 6:40 PM