Advertisement
Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.
Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics
Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.
Finance Executive Email Compromise via Native Windows Tools
A monthslong campaign targeted a global stock exchange executive, leveraging native Windows tools for persistence and unauthorized email monitoring.
Microsoft Coreutils for Windows: Security and Memory Safety Analysis
Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.
Weaponized Trust: Analyzing the Abuse of Administrative Utilities
Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.
GopherWhisper APT Abuses Legitimate Services in Government Attacks
China-linked APT GopherWhisper targets Southeast Asian governments using Go-based backdoors and legitimate cloud services for stealthy C2 communications.
Advertisement
Microsoft Defender Binaries Exploited as Attack Tools
Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.
Mitigating the Rise of Trusted Tool Abuse in Modern Cyberattacks
Explore why threat actors are pivoting from malware to Living-off-the-Land (LotL) techniques by abusing trusted administrative tools and native binaries.