home.social

#powershell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #powershell, aggregated by home.social.

fetched live
  1. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

    Pulse ID: 6a678b1bffd8195d4d34ef68
    Pulse Link: otx.alienvault.com/pulse/6a678
    Pulse Author: AlienVault
    Created: 2026-07-27 16:45:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault

  2. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

    Pulse ID: 6a678b1bffd8195d4d34ef68
    Pulse Link: otx.alienvault.com/pulse/6a678
    Pulse Author: AlienVault
    Created: 2026-07-27 16:45:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault

  3. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  4. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  5. Claude Code в Telegram голосом: свой мост, когда официальный канал выключен

    MCP-сервер отвечает Connected. Инструменты работают: бот сам присылает мне сообщения. Мои сообщения до бота доходят, я вижу их в очереди Telegram. А в сессию Claude Code они не попадают. Ни ошибки, ни предупреждения. Полтора часа я искал не там. Меня зовут Сол ГудКод, и обычно я вытаскиваю людей из ситуаций, в которые они сами себя загнали, но на этот раз клиентом оказался я сам: мне нужен был бот, которому можно наговорить задачу голосом из дороги, чтобы он сделал её на моей машине и в моих проектах. У Anthropic такое есть официально, и именно поэтому история вышла длиннее, чем я рассчитывал. Внутри: как отличить эту тишину от своей ошибки за минуту и чем я заменил официальный канал. Плюс восемь мест, где я наступил на грабли Windows. В том числе на те, куда уже наступал в этом же проекте. И на ту, где Claude вежливо попросил меня договорить мысль.

    habr.com/ru/articles/1063578/

    #claude_code #телеграмбот #anthropic #ииагенты #llm #whisper #fasterwhisper #powershell #голосовое_управление #mcp

  6. Do we talk enough about mental health in #IT?

    At #PSConfEU, @[email protected] shares:
    ✅ How to recognise when someone is struggling
    ✅ Why listening matters more than fixing
    ✅ The importance of open conversations

    👉 youtu.be/qLZcoTOF514?si=FKx...

    #PowerShell #Conference #Wellbeing

    - YouTube

  7. Do we talk enough about mental health in #IT?

    At #PSConfEU, @[email protected] shares:
    ✅ How to recognise when someone is struggling
    ✅ Why listening matters more than fixing
    ✅ The importance of open conversations

    👉 youtu.be/qLZcoTOF514?si=FKx...

    #PowerShell #Conference #Wellbeing

    - YouTube

  8. Here's a command that could help some of you. This thing I thought of prints all branches of a repo to a text file in the parrent folder from where you are. $ git branch --format="%(refname:short)" | Out-File "..\my-branches.txt" #Git #Github #Powershell

  9. Here's a command that could help some of you. This thing I thought of prints all branches of a repo to a text file in the parrent folder from where you are. $ git branch --format="%(refname:short)" | Out-File "..\my-branches.txt" #Git #Github #Powershell

  10. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  11. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  12. PowerShell enthusiasts, rejoice! PowerShell Weekly for July 24, 2026 is out now. Discover new ways to streamline your tasks and boost productivity.
    #PowerShell #Automation #TechNews
    psweekly.dowst.dev/?p=9103

  13. PowerShell enthusiasts, rejoice! PowerShell Weekly for July 24, 2026 is out now. Discover new ways to streamline your tasks and boost productivity.
    #PowerShell #Automation #TechNews
    psweekly.dowst.dev/?p=9103

  14. I just added a "scripts" repository to my #Github : github.com/joseph-w-allen/scri

    Right now it just has a few simple #bash things I made for personal use, but at some point I'll dig through my variuos #Python , #PowerShell , CTF, and course folders for more interesting stuff.

    I'll also update it with anything new I come up with, in case anyone else finds them useful.

    It's been a little while since I've used git and Github anyway, and I could use the practice while I'm applying for all these jobs.

  15. Curious about creating a TUI-base #PowerShell tool? Take a look at the PSTuiTools (github.com/jdhitsolutions/PSTu) module for practical examples. Or use the tools for your own entertainment.

  16. Curious about creating a TUI-base tool? Take a look at the PSTuiTools (github.com/jdhitsolutions/PSTu) module for practical examples. Or use the tools for your own entertainment.

  17. *checks Microsoft Docs for correct syntax/example of an MgGraph set command*

    ofc it doesn't actually work in a real setting

    #msgraph #powershell #azure

  18. Are you validating your #PowerShell code before CI?

    At #PSConfEU, Martin Howlett shows how to:
    ✅ Run validation locally
    ✅ Use Invoke-Build validate everywhere
    ✅ Align dev, CI & #AI workflows

    Same checks, everywhere.

    👉 youtu.be/4aaSfI597Q0?si=rmp...

    #automation #IT #DevOps #Conference

    - YouTube

  19. Are you validating your #PowerShell code before CI?

    At #PSConfEU, Martin Howlett shows how to:
    ✅ Run validation locally
    ✅ Use Invoke-Build validate everywhere
    ✅ Align dev, CI & #AI workflows

    Same checks, everywhere.

    👉 youtu.be/4aaSfI597Q0?si=rmp...

    #automation #IT #DevOps #Conference

    - YouTube

  20. Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

    A sophisticated phishing campaign impersonates legitimate business entities including UPS and the Malaysian Inland Revenue Board to distribute Phantom Stealer v3.5.0. The attack begins with convincing emails containing compressed archives housing malicious JavaScript files. Once executed, the JavaScript launches obfuscated PowerShell scripts that operate entirely in memory, deploying multiple stages of encrypted and encoded payloads. The infection chain utilizes Base64 encoding, AES encryption, and XOR ciphering to conceal its activities. The final payload, Phantom Stealer, harvests credentials from browsers, cryptocurrency wallets, messaging applications, and system information before exfiltrating stolen data via SMTP over port 587 using STARTTLS encryption. The multi-layered approach significantly reduces on-disk footprint and employs reflective code loading and process injection into legitimate binaries to evade traditional security defenses.

    Pulse ID: 6a60df1ccbee3728dd9c71e5
    Pulse Link: otx.alienvault.com/pulse/6a60d
    Pulse Author: AlienVault
    Created: 2026-07-22 15:17:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Email #Encryption #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Rust #TLS #bot #cryptocurrency #AlienVault

  21. Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

    A sophisticated phishing campaign impersonates legitimate business entities including UPS and the Malaysian Inland Revenue Board to distribute Phantom Stealer v3.5.0. The attack begins with convincing emails containing compressed archives housing malicious JavaScript files. Once executed, the JavaScript launches obfuscated PowerShell scripts that operate entirely in memory, deploying multiple stages of encrypted and encoded payloads. The infection chain utilizes Base64 encoding, AES encryption, and XOR ciphering to conceal its activities. The final payload, Phantom Stealer, harvests credentials from browsers, cryptocurrency wallets, messaging applications, and system information before exfiltrating stolen data via SMTP over port 587 using STARTTLS encryption. The multi-layered approach significantly reduces on-disk footprint and employs reflective code loading and process injection into legitimate binaries to evade traditional security defenses.

    Pulse ID: 6a60df1ccbee3728dd9c71e5
    Pulse Link: otx.alienvault.com/pulse/6a60d
    Pulse Author: AlienVault
    Created: 2026-07-22 15:17:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Email #Encryption #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Rust #TLS #bot #cryptocurrency #AlienVault

  22. Inside a TrickBot Variant Using DNS Tunneling for C2

    A TrickBot variant has been identified that uses DNS tunneling for command-and-control communications instead of traditional HTTP protocols. The malware maintains persistence through Windows Task Scheduler, creating disguised tasks that execute at startup and repeat every five minutes. Configuration data is stored in NTFS Alternate Data Streams to evade detection. The malware employs multiple obfuscation techniques including encrypted strings, runtime API resolution via hash-based lookups, and dynamically calculated constants. Its modular architecture supports twelve different control commands enabling capabilities such as module downloads, process injection through hollowing and doppelgänging techniques, PowerShell execution, and raw machine code execution. The variant transfers data through specially crafted DNS queries to public DNS servers, encoding command data in malformed domain names and receiving responses embedded within multiple IPv4 addresses, achieving transfer speeds of approximately 30.7 KB/s.

    Pulse ID: 6a6120390f602b6ee56739c3
    Pulse Link: otx.alienvault.com/pulse/6a612
    Pulse Author: AlienVault
    Created: 2026-07-22 19:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #HTTP #InfoSec #Mac #Malware #OTX #OpenThreatExchange #PowerShell #RAT #Windows #bot #AlienVault

  23. Inside a TrickBot Variant Using DNS Tunneling for C2

    A TrickBot variant has been identified that uses DNS tunneling for command-and-control communications instead of traditional HTTP protocols. The malware maintains persistence through Windows Task Scheduler, creating disguised tasks that execute at startup and repeat every five minutes. Configuration data is stored in NTFS Alternate Data Streams to evade detection. The malware employs multiple obfuscation techniques including encrypted strings, runtime API resolution via hash-based lookups, and dynamically calculated constants. Its modular architecture supports twelve different control commands enabling capabilities such as module downloads, process injection through hollowing and doppelgänging techniques, PowerShell execution, and raw machine code execution. The variant transfers data through specially crafted DNS queries to public DNS servers, encoding command data in malformed domain names and receiving responses embedded within multiple IPv4 addresses, achieving transfer speeds of approximately 30.7 KB/s.

    Pulse ID: 6a6120390f602b6ee56739c3
    Pulse Link: otx.alienvault.com/pulse/6a612
    Pulse Author: AlienVault
    Created: 2026-07-22 19:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #HTTP #InfoSec #Mac #Malware #OTX #OpenThreatExchange #PowerShell #RAT #Windows #bot #AlienVault

  24. Can #Bicep improve how we write #DSC configs?

    At #PSConfEU, Andy Jordan shows:
    ✅ Strong typing & IntelliSense
    ✅ Loops & orchestration
    ✅ Better config authoring

    👉 youtu.be/5_m6estlXxs?si=mPo...

    #PowerShell #automation #IT #DevOps #Conference

    - YouTube

  25. Can #Bicep improve how we write #DSC configs?

    At #PSConfEU, Andy Jordan shows:
    ✅ Strong typing & IntelliSense
    ✅ Loops & orchestration
    ✅ Better config authoring

    👉 youtu.be/5_m6estlXxs?si=mPo...

    #PowerShell #automation #IT #DevOps #Conference

    - YouTube

  26. Become a #PowerShell scripting master and save with my eBook bundle from Leanpub(leanpub.com/b/masterpowershell). There is always something new to learn.

  27. Become a scripting master and save with my eBook bundle from Leanpub(leanpub.com/b/masterpowershell). There is always something new to learn.

  28. Need to bulk reset AD user passwords from a CSV? This PowerShell snippet processes each user, handles errors, logs success/failure, and forces password change at next logon. Works on Windows Server 2016-2022. #windows #snippet #powershell

    valtersit.com/vault/bulk-reset

  29. Are your #PowerShell standards actually enforced?

    At #PSConfEU, @[email protected] shows how to:
    ✅ Build custom PSScriptAnalyzer rules
    ✅ Inspect code via AST
    ✅ Enforce checks in CI/CD

    👉 youtu.be/7Hw7bvgj2hk?si=Hfj...

    #automation #IT #DevOps #Conference

    - YouTube