Living Off the Land

Introduction

Windows Sysinternals

LOLBAS Project

File Operations

File Execution

Application Whitelisting Bypasses

Other Techniques

Real-life Scenario

Astaroth: Banking Trojanarrow-up-right

Microsoft Discovers Fileless Malware Campaign Dropping Astaroth Info Stealerarrow-up-right

Astaroth malware hides command servers in YouTube channel descriptionsarrow-up-right

Conclusion

Last updated