Threats Tagged 'amsi bypass'
View all threats tagged with 'amsi bypass'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'amsi bypass'
Click on any threat for detailed analysis and mitigation recommendations
A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking. Join the discussion | AlienVault OTX General | 07/07/2026, 23:19:29 UTC Added: 07/09/2026, 11:32:31 UTC |
A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise. Join the discussion | AlienVault OTX General | 07/07/2026, 14:14:56 UTC Added: 07/07/2026, 14:28:23 UTC |
DesckVB RAT emerged in February 2026 through a sophisticated malspam campaign utilizing a dynamic delivery kit that personalizes lures on-the-fly by extracting victim email addresses and pulling company logos in real-time. The attack chain routes through Google's DoubleClick domain to evade email gateways before delivering a five-stage infection: HTML redirect, JScript loader, PowerShell dropper, .NET loader, and finally the RAT itself. The malware employs extensive anti-analysis techniques including sandbox detection, forced reboots upon detection, and in-memory execution via .NET reflection. Once established, it patches AMSI and ETW at the native API level, injects into legitimate Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe, and establishes persistence through registry keys and scheduled tasks. The RAT communicates with DDNS-based C2 infrastructure on non-standard ports, performs system reconnaissance including GPU enumeration possibly for crypto mining, and can deliver additional payl... Join the discussion | AlienVault OTX General | 06/03/2026, 13:18:22 UTC Added: 06/04/2026, 08:48:45 UTC |
A sophisticated multi-stage intrusion campaign was identified leveraging a weaponized PowerShell payload disguised as a JPEG image file (sysupdate.jpeg) to deploy a trojanized ConnectWise ScreenConnect instance for covert remote access. The attack likely originates through social engineering techniques including phishing emails or malicious attachments. Upon execution, the malware establishes a staging environment, retrieves additional payloads from attacker-controlled infrastructure, and dynamically compiles a custom launcher using Microsoft's legitimate .NET compiler (csc.exe) to evade detection. The intrusion abuses ComputerDefaults.exe and a malicious ms-settings registry hijack to perform a fileless UAC bypass and obtain elevated privileges. Once elevated, the malware deploys a persistent service masquerading as OneDriveServers and launches a modified ScreenConnect framework capable of credential interception, remote command execution, surveillance operations, SYSTEM-level execution, encrypted command... Join the discussion | AlienVault OTX General | 05/10/2026, 13:09:22 UTC Added: 05/11/2026, 10:06:23 UTC |
A Microsoft Teams voice-phishing campaign leveraging Quick Assist, a remote administration tool, was tracked in September 2025. The campaign uses help desk scams to gain initial access, followed by user group enumeration and the execution of a PowerShell script to download a command and control payload. The attack employs AMSI bypass, encrypted communications, and a web-socket remote access trojan. Multiple Microsoft 365 tenants with IT-related subdomains were used, along with various IPs and domains for C2 infrastructure. The campaign shows similarities to Storm-1811 and PhantomCaptcha activities, suggesting a complex cybercrime ecosystem. The attackers' ultimate goal may be ransomware deployment, although observed attempts were successfully blocked. Join the discussion | AlienVault OTX General | 02/02/2026, 10:52:24 UTC Added: 02/02/2026, 11:00:08 UTC |
Turla's Kazuar v3 loader employs sophisticated techniques to evade detection. It uses a VBScript to drop files and execute a native loader, which bypasses security measures and leverages COM for stealth. The loader utilizes control flow redirection, patchless ETW and AMSI bypasses, and COM integration to decrypt and execute three Kazuar v3 payloads (KERNEL, WORKER, BRIDGE) in memory. The attack chain is designed to be resilient and stealthy, exploiting trusted system processes to avoid detection. The malware uses modular architecture and COM subsystem integration to maintain a low profile while carrying out its malicious activities. Join the discussion | AlienVault OTX General | 01/15/2026, 15:21:06 UTC Added: 01/15/2026, 15:33:12 UTC |
Since the release of XWorm V6.0 on June 4, 2025, we have noted a surge in samples identified as XWorm V6.0 on VirusTotal, reflecting its rapid adoption by threat actors. One prominent campaign illustrates its delivery: a malicious JavaScript (JS) file initiates a PowerShell (PS1) script, which deploys an injector to deliver the XWorm Client. Join the discussion | AlienVault OTX General | 10/06/2025, 18:58:53 UTC Added: 10/06/2025, 19:03:49 UTC |
A threat group dubbed NoisyBear has been targeting Kazakhstan's oil and gas sector since April 2025. The campaign focuses on KazMunaiGas employees, using spear-phishing emails with malicious attachments. The infection chain involves a ZIP file containing a malicious LNK file and decoy document, which downloads a batch script, leading to PowerShell loaders (DOWNSHELL) and ultimately a malicious DLL implant. The threat actor uses various techniques including AMSI bypass, process injection, and reflective DLL loading. Infrastructure analysis reveals the use of sanctioned hosting providers and open-source post-exploitation tools. The group is believed to be of Russian origin based on language artifacts and targeting patterns. Join the discussion | AlienVault OTX General | 09/05/2025, 17:17:06 UTC Added: 09/05/2025, 19:41:37 UTC |
A threat group dubbed NoisyBear has been targeting Kazakhstan's oil and gas sector since April 2025, particularly focusing on KazMunaiGas employees. The campaign uses spear-phishing emails with malicious ZIP attachments containing LNK files. These files download batch scripts, which in turn retrieve PowerShell loaders dubbed DOWNSHELL. The infection chain progresses through multiple stages, ultimately leading to the deployment of a malicious DLL implant. The threat actor employs various techniques to evade detection, including AMSI bypass and reflective DLL injection. The infrastructure used by NoisyBear is hosted on sanctioned web services, and the group is suspected to be of Russian origin based on language artifacts and targeting patterns. Join the discussion | AlienVault OTX General | 09/04/2025, 09:23:43 UTC Added: 09/04/2025, 21:09:06 UTC |
A new version of XWorm malware (version 6.0) has been discovered, showcasing advanced features for persistence and evasion. The infection chain begins with a VBScript that downloads and executes a PowerShell script. This script implements an AMSI bypass by modifying CLR.DLL in memory, then downloads and loads the XWorm binary. The latest version includes the ability to run as a critical process, preventing termination without admin privileges. It also introduces new anti-analysis techniques, such as terminating on Windows XP and detecting execution in data centers or hosting providers. The malware maintains its in-memory execution and continues to employ various evasion techniques. Join the discussion | AlienVault OTX General | 07/30/2025, 19:01:41 UTC Added: 07/30/2025, 19:17:47 UTC |
Showing 1 to 10 of 10 results