PowerShell Loader Delivering Credential-Stealing Payload
- Business Impact
- A macro-enabled document dropped an obfuscated PowerShell loader that fetched a second-stage binary designed to harvest browser credentials and beacon to an attacker-controlled domain, providing a foothold for further intrusion.
- Recommendation
- Block the identified domains and hashes, rotate exposed credentials on affected users, enforce macro restrictions and constrained language mode for PowerShell, and deploy the provided detection rules to catch similar loaders.