Detection of .NET Proxy Execution via Script-Based Launchers
Adversaries are leveraging trusted .NET utilities spawned by scripts in user-writable directories to execute code and maintain persistence, a technique observed in recent VIP Keylogger campaigns.
Security research has identified a persistent technique utilized by the VIP Keylogger malware family to achieve defense evasion and code execution. Attackers utilize legitimate, signed .NET framework utilities - specifically aspnet_compiler.exe, msbuild.exe, regasm.exe, InstallUtil.exe, and vbc.exe - as proxies to run malicious code. The execution is typically initiated by script-based parents, such as batch files, PowerShell, or VBScript, originating from low-trust or user-writable directories including Temp, AppData, or the Recycle Bin.
This approach masks the execution of malicious payloads by wrapping them in trusted binary processes, effectively bypassing simple signature-based detection. Defenders should focus on monitoring parent-child process relationships where these specific .NET binaries are launched by script interpreters from suspicious file system paths. This behavior is highly anomalous in production environments and warrants immediate investigation when detected.
Attack Chain
- Attacker drops a malicious script (e.g., .bat, .vbs, .ps1) into a user-writable directory such as %TEMP% or C:\Users\Public.
- The malicious script is executed by the user or through an initial access trigger (e.g., phishing attachment, drive-by download).
- The script launches a legitimate .NET utility (e.g., msbuild.exe or regasm.exe) to avoid detection by security software.
- The .NET utility is instructed via command-line arguments or configuration files to execute secondary code or malicious DLLs.
- The parent script process terminates or remains resident to continue the execution flow.
- The .NET utility performs the intended malicious objective, such as credential theft or establishing C2 communication.
- Data exfiltration or secondary payload staging is executed under the context of the trusted Microsoft-signed binary.
Impact
Successful exploitation allows for stealthy code execution on Windows endpoints, enabling malware like the VIP Keylogger to operate undetected. This can lead to full system compromise, exfiltration of sensitive user data, and persistence establishment within the enterprise environment.
Recommendation
- Deploy the provided Sigma rule to identify anomalous parent-child process relationships between script interpreters and .NET utilities.
- Configure EDR telemetry to capture full command-line arguments and process GUIDs for all child processes spawned by script interpreters.
- Restrict execution permissions for scripts and non-administrative binaries within high-risk directories such as \Temp, \Public, and \AppData\Local\Temp.
- Perform periodic threat hunting for parent-child pairings of scripting engines spawning binaries listed in the detection rule.
Immediate actions
Deploy the Sigma detection rule to identify .NET utility proxy execution.
Threat Hunt
Search for script interpreters (powershell.exe, cmd.exe) executing binaries from \Temp\ or \AppData\ paths.
Data: Process creation logs with parent and image paths
Mitigations
Implement AppLocker or WDAC policies to restrict execution from user-writable directories.
Technique T1218
Detection coverage 1
Detect Proxy Execution of .NET Utilities via Scripts
mediumDetects .NET binaries spawned by script interpreters from suspicious user-writable locations.
Detection queries are available on the platform. Get full rules →