The beacon that won't decrypt unless it beats AMSI: pulling apart a WMI-launched PowerShell loader
A WMI-launched PowerShell loader with reflection AMSI/ETW bypass and a payload that only decrypts if its own AMSI bypass succeeded first.
A WMI-launched PowerShell loader with reflection AMSI/ETW bypass and a payload that only decrypts if its own AMSI bypass succeeded first.
A PowerShell stager drops the legitimate Node.js runtime, runs a JavaScript RAT under it, and resolves its C2 domain from a TON blockchain smart contract.
A ClickFix lure drops a 145 MB Electron flomo app. The RAT runs a signed OneDriveLauncher that sideloads a trojanized DLL to decrypt a PNG-wrapped payload.
A ClickFix loader using finger.exe over TCP/79 to drop IronPython and an in-process x86 shellcode beacon.
A ClickFix campaign drops a 2.4 MB polyglot from prism-vertex[.]com that looks like an MSIX package but parses as an HTA when mshta opens it.
A 3.7 MB log-line file in System32\drivers\, a tiny PowerShell read-decode-execute, and an HTTP beacon that pulls its capability live.