Skip to main content
← All Articles

Tag

#PowerShell

17 articles

Advertisement

HIGH
Threat Intel

Faronics Deploy Abused by Phishing Actors to Install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.

Runtime Rebel Intel
4 min read · Sep 2, 2026
TerminalFix: PowerShell Weaponization in Enterprise Attacks
HIGH
Threat Intel

TerminalFix: PowerShell Weaponization in Enterprise Attacks

Analysis of 'TerminalFix' campaign, detailing PowerShell weaponization, multistage attack chain, and reverse tunnels into enterprise networks.

Runtime Rebel Intel
4 min read · Sep 1, 2026
INFO
Malware

DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files

Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.

Runtime Rebel Intel
4 min read · Aug 24, 2026
MEDIUM
Threat Intel

Entra Log Analysis: Detecting Password Spray Attacks with PowerShell

Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.

Runtime Rebel Intel
4 min read · Aug 21, 2026
INFO
Threat Intel

Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph

A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.

Runtime Rebel Intel
4 min read · Aug 21, 2026
MEDIUM
Threat Intel

PowerShell and WMI Detection: Analyzing Suspicious Command Lines

Learn to detect obfuscated PowerShell commands and malicious WMI activity through advanced command-line monitoring and log analysis for security teams.

Runtime Rebel Intel
3 min read · Jul 17, 2026

Advertisement

HIGH
Malware

Analyzing Remcos RAT Delivery via Malicious LNK Files

Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.

Runtime Rebel Intel
4 min read · Jul 13, 2026
HIGH
Malware

Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell

Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.

Runtime Rebel Intel
5 min read · Jul 6, 2026
HIGH
Malware

Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT

Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.

Runtime Rebel Intel
3 min read · Jun 23, 2026
HIGH
Malware

NetSupport RAT Infection: How to Detect Unidentified Loader Exploits

Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.

Runtime Rebel Intel
4 min read · Jun 1, 2026
Weaponized Trust: Analyzing the Abuse of Administrative Utilities
MEDIUM
Threat Intel

Weaponized Trust: Analyzing the Abuse of Administrative Utilities

Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.

Runtime Rebel Intel
3 min read · May 15, 2026
PowMix Botnet Targets Czech Workers via Randomized C2 Traffic
HIGH
Threat Intel

PowMix Botnet Targets Czech Workers via Randomized C2 Traffic

Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.

Runtime Rebel Intel
3 min read · Apr 16, 2026
DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea
MEDIUM
Threat Intel

DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea

North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.

Runtime Rebel Intel
4 min read · Apr 6, 2026
HIGH
Malware

SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives

Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.

Runtime Rebel Intel
4 min read · Mar 25, 2026
HIGH
Malware

InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers

The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.

Runtime Rebel Intel
4 min read · Mar 9, 2026
MEDIUM
Malware

XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains

New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.

Runtime Rebel Intel
3 min read · Mar 4, 2026
Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell
HIGH
Malware

Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell

Security researchers identify a malware campaign using trojanized gaming tools to deliver a Java-based RAT using PowerShell and portable Java runtimes.

Runtime Rebel Intel
4 min read · Feb 27, 2026