Skip to main content
← All Articles

Tag

#Living-off-the-Land

8 articles

Advertisement

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
MEDIUM
Threat Intel

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime

Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.

Runtime Rebel Intel
4 min read · Sep 3, 2026
INFO
Threat Intel

Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics

Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.

Runtime Rebel Intel
2 min read · Aug 18, 2026
Finance Executive Email Compromise via Native Windows Tools
HIGH
Threat Intel

Finance Executive Email Compromise via Native Windows Tools

A monthslong campaign targeted a global stock exchange executive, leveraging native Windows tools for persistence and unauthorized email monitoring.

Runtime Rebel Intel
3 min read · Jun 3, 2026
INFO
Threat Intel

Microsoft Coreutils for Windows: Security and Memory Safety Analysis

Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.

Runtime Rebel Intel
3 min read · Jun 3, 2026
Weaponized Trust: Analyzing the Abuse of Administrative Utilities
MEDIUM
Threat Intel

Weaponized Trust: Analyzing the Abuse of Administrative Utilities

Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.

Runtime Rebel Intel
3 min read · May 15, 2026
MEDIUM
Threat Intel

GopherWhisper APT Abuses Legitimate Services in Government Attacks

China-linked APT GopherWhisper targets Southeast Asian governments using Go-based backdoors and legitimate cloud services for stealthy C2 communications.

Runtime Rebel Intel
3 min read · Apr 25, 2026

Advertisement

Microsoft Defender Binaries Exploited as Attack Tools
MEDIUM
Threat Intel

Microsoft Defender Binaries Exploited as Attack Tools

Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.

Runtime Rebel Intel
3 min read · Apr 22, 2026
Mitigating the Rise of Trusted Tool Abuse in Modern Cyberattacks
MEDIUM
Threat Intel

Mitigating the Rise of Trusted Tool Abuse in Modern Cyberattacks

Explore why threat actors are pivoting from malware to Living-off-the-Land (LotL) techniques by abusing trusted administrative tools and native binaries.

Runtime Rebel Intel
3 min read · Apr 1, 2026