Threat researchers documented multiple campaigns abusing Microsoft Build Engine (MSBuild.exe) as a living-off-the-land binary to compile and execute malicious code in memory, helping attackers bypass application controls and reduce disk artifacts. Cisco Talos reviewed more than 100 suspicious MSBuild project files and found frequent use of inline tasks to launch post-exploitation tooling such as Cobalt Strike, Meterpreter, Covenant, Silent Trinity, and Mimikatz, often after initial access from Office macros, HTA files, or browser-driven delivery chains. MITRE maps this behavior to technique T1127, reflecting the use of trusted developer utilities for defense evasion and execution.
The same tradecraft appeared across distinct intrusion sets and malware families. Zscaler described a targeted campaign in which macro-enabled Word documents wrote obfuscated C# code to disk and used csc.exe and MSBuild.exe to compile and deploy the previously unreported ShellReset RAT, which supported remote shell access, file transfer, directory listing, and screenshot capture. AhnLab reported attackers compromising exposed Microsoft SQL Server instances and then launching MSBuild.exe to inject a Cobalt Strike beacon into wwanmm.dll, while QiAnXin linked a Kashmir-themed campaign to APT-C-09, which used a fake MSBuild.exe in %AppData% alongside GitHub and Feed43 dead-drop resolvers for command-and-control. Across the reporting, defenders were urged to prioritize detections for unusual parent-child process chains, especially Office applications, browsers, or SQL Server processes spawning MSBuild.exe.

Get the actors, campaigns, and ATT&CK mapping behind it.
12 events from the most recent confirmed update back to the earliest known activity.
AhnLab listed the file detection signature Trojan/Win.FDFM.C4959286 dated 2022.02.09.00. This was one of the latest dated detections included in the report on Cobalt Strike being distributed to unsecured MS-SQL servers.
AhnLab listed several detections on 2022-02-01, 2022-02-03, and 2022-02-04, including Generic, AgentTesla, Infostealer, and Injector signatures associated with the observed MS-SQL intrusion activity. These detections preceded the later reporting on Cobalt Strike distribution via unsecured SQL servers.
AhnLab listed the detection signature Trojan/Win.Agent.C4897376 dated 2022.01.05.02 among indicators associated with the MS-SQL-targeting campaign. The report later connected related activity to Cobalt Strike delivery through compromised SQL servers.
A malicious document named "Get Stared.doc" was hosted at misrmarket[.]xyz on 2020-05-19. The lure copied text from the legitimate site datacoup.com for social engineering.
The domain misrmarket[.]xyz, which spoofed anonfiles.com and was later used in the ShellReset infection chain, was registered on 2020-02-26 according to Whois data. The campaign used it to host lure documents and retrieve follow-on payload components.
Malicious Word documents named "5G Expo.doc" and "FutureBuild.doc" were hosted at documentsharing[.]space on 2020-02-24. Researchers later attributed these lures to the ShellReset campaign based on shared TTPs.
Researchers observed four malicious Word documents in February 2020 and May 2020 and attributed them to the same threat actor based on similar TTPs. The campaign used macro-enabled lures and trusted Windows utilities including csc.exe and msbuild.exe to deploy the ShellReset RAT.
The domain documentsharing[.]space, later used to host malicious Word lure documents in the ShellReset campaign, was registered on 2019-10-21 according to Whois records. Researchers later tied hosted lures on this domain to the same threat actor.
The XLSM lure document "India makes Kashmir Dangerous Place in the World.xlsm" was uploaded to VirusTotal on 2019-08-13 05:05:15. QiAnXin analyzed the sample as part of an APT-C-09-linked targeted attack campaign.
The dropped payload masquerading as %AppData%\MSBuild.exe had a compile time of 2019-08-08 14:00:32. This payload was later used in a targeted campaign exploiting CVE-2017-11882 and dead-drop C2 resolution.
The GitHub account petersonmike, later used to host encrypted configuration data for the analyzed malware, was created on 2019-08-07 according to the report. The malware retrieved one of its dead-drop configurations from this account's repository.
QiAnXin assessed that GitHub-hosted configuration infrastructure associated with the APT-C-09 activity cluster dated back to at least 2018-07-03. The actor was later linked to at least 44 GitHub-hosted configuration files used as dead-drop resolvers for C2 configuration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 94 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceasec.ahnlab.com
Open sourceblog.talosintelligence.com
Open sourceti.qianxin.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.