Skip to content
Threat Feed
medium advisory

Detection of .NET Proxy Execution via Script-Based Launchers

Adversaries are leveraging trusted .NET utilities spawned by scripts in user-writable directories to execute code and maintain persistence, a technique observed in recent VIP Keylogger campaigns.

Security research has identified a persistent technique utilized by the VIP Keylogger malware family to achieve defense evasion and code execution. Attackers utilize legitimate, signed .NET framework utilities - specifically aspnet_compiler.exe, msbuild.exe, regasm.exe, InstallUtil.exe, and vbc.exe - as proxies to run malicious code. The execution is typically initiated by script-based parents, such as batch files, PowerShell, or VBScript, originating from low-trust or user-writable directories including Temp, AppData, or the Recycle Bin.

This approach masks the execution of malicious payloads by wrapping them in trusted binary processes, effectively bypassing simple signature-based detection. Defenders should focus on monitoring parent-child process relationships where these specific .NET binaries are launched by script interpreters from suspicious file system paths. This behavior is highly anomalous in production environments and warrants immediate investigation when detected.

Attack Chain

  1. Attacker drops a malicious script (e.g., .bat, .vbs, .ps1) into a user-writable directory such as %TEMP% or C:\Users\Public.
  2. The malicious script is executed by the user or through an initial access trigger (e.g., phishing attachment, drive-by download).
  3. The script launches a legitimate .NET utility (e.g., msbuild.exe or regasm.exe) to avoid detection by security software.
  4. The .NET utility is instructed via command-line arguments or configuration files to execute secondary code or malicious DLLs.
  5. The parent script process terminates or remains resident to continue the execution flow.
  6. The .NET utility performs the intended malicious objective, such as credential theft or establishing C2 communication.
  7. Data exfiltration or secondary payload staging is executed under the context of the trusted Microsoft-signed binary.

Impact

Successful exploitation allows for stealthy code execution on Windows endpoints, enabling malware like the VIP Keylogger to operate undetected. This can lead to full system compromise, exfiltration of sensitive user data, and persistence establishment within the enterprise environment.

Recommendation

  1. Deploy the provided Sigma rule to identify anomalous parent-child process relationships between script interpreters and .NET utilities.
  2. Configure EDR telemetry to capture full command-line arguments and process GUIDs for all child processes spawned by script interpreters.
  3. Restrict execution permissions for scripts and non-administrative binaries within high-risk directories such as \Temp, \Public, and \AppData\Local\Temp.
  4. Perform periodic threat hunting for parent-child pairings of scripting engines spawning binaries listed in the detection rule.

Immediate actions

Deploy the Sigma detection rule to identify .NET utility proxy execution.

Detection Engineering 24h

Threat Hunt

Search for script interpreters (powershell.exe, cmd.exe) executing binaries from \Temp\ or \AppData\ paths.

T1218 high high confidence hunt now

Data: Process creation logs with parent and image paths

Mitigations

Implement AppLocker or WDAC policies to restrict execution from user-writable directories.

medium_term IT Operations

Technique T1218

Detection coverage 1

Detect Proxy Execution of .NET Utilities via Scripts

medium

Detects .NET binaries spawned by script interpreters from suspicious user-writable locations.

sigma tactics: defense_evasion, execution techniques: T1218 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →