Researchers documented ScriptBlock Smuggling, a PowerShell technique that can spoof benign content in Script Block Logging and help bypass AMSI inspection without using reflection or patching. The method abuses how PowerShell handles script blocks so that security tooling may record an innocuous command while a different payload executes, creating a misleading audit trail for defenders reviewing event 4104 logs.
Follow-up forensic testing found the technique does not fully erase evidence of malicious activity. In lab experiments, Script Block Logging captured the spoofed command, but the surrounding smuggling logic and PowerShell Module Logging event 4103 still revealed execution details, including a proof of concept that used Invoke-WebRequest to download a file. Researchers also noted reports that the approach had been adapted for Vidar Stealer delivery, while Microsoft Defender and AMSI still detected the tested samples as malicious, indicating the technique can hinder visibility but not eliminate forensic traces.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The same testing showed that PowerShell Module Logging event 4103 still captured meaningful evidence of the executed code, while AMSI and Windows Defender detected the smuggling code as malicious and blocked execution in the lab.
In lab testing, dfir.ch found that PowerShell Script Block Logging event 4104 recorded the spoofed benign command rather than the executed malicious command, and the executed AST did not appear as a separate Script Block Logging entry.
BC-Security presented "ScriptBlock Smuggling," a PowerShell technique described as spoofing arbitrary messages into Script Block logs while bypassing AMSI without reflection or memory patching.
According to X user @thomasmechen, attackers quickly adapted ScriptBlock Smuggling and used it to spread Vidar Stealer. The dfir.ch analysis also cites a more elaborate example posted by Nasreddine.
AtomicsonaFri announced a new Atomic Red Team test for ScriptBlock Smuggling. The test builds separate spoofed and executed ASTs, combines them into a new ScriptBlockAst, and invokes the resulting script block.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.