Summary:
A threat actor associated with the LockBit 3.0 ransomware operation is abusing the Windows Defender command line tool to load Cobalt Strike beacons on compromised systems and evade detection by security software. In a recent incident, researcher noticed the abuse of Microsoft Defender’s command line tool “MpCmdRun.exe” to side-load malicious DLLs that decrypt and install Cobalt Strike beacons. The initial network compromise in both cases were conducted by exploiting a Log4j flaw on vulnerable VMWare Horizon Servers to run PowerShell code.[/subscribe_to_unlock_form]
Summary:
A threat actor associated with the LockBit 3.0 ransomware operation is abusing the Windows Defender command line tool to load Cobalt Strike beacons on compromised systems and evade detection by security software. In a recent incident, researcher noticed the abuse of Microsoft Defender’s command line tool “MpCmdRun.exe” to side-load malicious DLLs that decrypt and install Cobalt Strike beacons. The initial network compromise in both cases were conducted by exploiting a Log4j flaw on vulnerable VMWare Horizon Servers to run PowerShell code.[emaillocker id="1283"]
References:
The following reports contain further technical details:
[/emaillocker]