Threat researchers report that attackers and malware operators continue to bypass Microsoft’s Antimalware Scan Interface (AMSI) on Windows, weakening a key inspection layer for PowerShell and other script-based activity. Recent telemetry highlighted two dominant techniques: tampering with PowerShell’s AmsiUtils state, including the amsiInitFailed flag, and patching AMSI-related code in memory—especially AmsiScanBuffer or amsi.dll—to force scan failures. Sophos said memory-patching now accounts for most observed AMSI bypass attempts and has appeared in activity involving Cobalt Strike, Agent Tesla downloaders, WannaMine, and intrusions linked to ProxyLogon exploitation.
Separate research showed that an older AMSI bypass using DLL hijacking can still work by planting a fake amsi.dll with the expected exports in specific directories, in some cases even without elevated privileges. SensePost said Microsoft did not assign a CVE because AMSI is not treated as a security boundary, but Windows Defender added detections that reduce the technique’s reliability for low-privileged users, and the PowerShell team was reported to be working on a fix. Researchers also noted that attackers may sidestep AMSI through PowerShell version downgrades, alternate scripting engines such as jscript or cscript, or other evasive tradecraft, reinforcing that AMSI should be backed by defense in depth and timely patching rather than relied on as a standalone control.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
In a 90-day telemetry period from February to May 2021, Sophos found that more than 98 percent of AMSI bypass attempts involved tampering with AMSI code in memory, while amsiInitFailed-based bypasses accounted for about 1 percent.
Windows Defender added detection for the AMSI DLL hijack technique, including detecting copied amsi.dll files in user-writable folders, reducing the technique's effectiveness for low-privileged users.
Matt Graeber published a one-line AMSI bypass that sets PowerShell's amsiInitFailed flag to true, causing the current PowerShell process to stop requesting AMSI scans.
The AMSI DLL hijacking issue was reported to the Microsoft Security Response Center, but Microsoft did not assign a CVE because AMSI was not considered a security boundary.
Microsoft introduced the Antimalware Scan Interface (AMSI) to let software request malware scans of files, memory, and streams in a vendor-agnostic way on Windows systems.
In March, Sophos detected repeated attempts to install a WannaMine payload on a customer's systems; one unprotected Windows system was infected while protected systems blocked execution despite continued spread attempts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.