
Hackers Hide Malware in 364 Environment Variables and Execute It Without Touching the Disk
It was first observed targeting a North America-based multinational software and SaaS provider, suggesting that similarly large enterprises could be at risk. Attackers deliver the first-stage Windows Script Host JScript file in a TAR archive disguised as a purchase order. Once opened, the script launches a hidden PowerShell process. It prepares an in-memory .NET payload […]
The post Hackers Hide Malware in 364 Environment Variables and Execute It Without Touching the Disk appeared first on Cyber Security News.