New Evasive Malware Technique exploits Microsoft Dynamic Exchange (DDE):
Dynamic Data Exchange (DDE) allows adversaries to deliver stealthy payloads via document files while avoiding the common usage of macro.
If the attacker places a malicious script under the path %USERPROFILE%\profile.ps1 and start PowerShell ISE, the script will be executed without powershell.exe being involved
Bypass execution policy: HKEY_CURRENT_USER\Software\MicrosoftPowerShell\1\ShellIds\Microsoft.PowerShell - And set the registry value ExecutionPolicy to Unrestricted.
regsvr32.exe, rundll32.exe, certutil.exe and schtasks.exe.
Living Off The Land Binaries and Scripts:
Abusing WMI to Build a Persistent, Asynchronous, and Fileless Backdoor:
APT29’s use of WMI and PowerShell to plant fileless backdoors:
Memory injection - VirtualAllocEx and WriteProcessMemory, which allow one process to write code into another process. Overview of the AZORult attack:
Wrap compiled executables into scripts that extract malicious payload into memory during runtime.
Process Doppelgänging - attacker misuses NTFS transaction capabilities built into Microsoft Windows to temporarily modify a trusted file in memory without committing changes to disk