Sub-technique of T1127 Trusted Developer Utilities Proxy Execution.View on attack.mitre.org
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.
Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual Basic code to be inserted into an XML project file. MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.
Rules on DetectionCode tagged with T1127.001.
| Rule | Level | Log source |
|---|---|---|
| Silenttrinity Stager Msbuild Activity | high | windows / network_connection |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| MSBuild Suspicious Spawned By Script Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious msbuild path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious MSBuild Rename | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious MSBuild Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| ToolEmpire | Empire can use built-in modules to abuse trusted utilities like MSBuild.exe. |
| MalwareNOOPLDR | NOOPLDR can be executed via MSBuild. |
| MalwarePlugX | A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques. |
| Used by | Procedure example |
|---|---|
| CampaignFrankenstein | During Frankenstein, the threat actors used MSbuild to execute an actor-created file. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.