Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Hackers love Microsoft's PowerShell
#1
[Image: powershell-e1460537936279.jpg]
PowerShell, a scripting language inherent to Microsoft operating systems, is largely used to launch cyber-attacks, a new report suggests.
The Unified Threat Research report, released by next-generation endpoint security (NGES) firm Carbon Black, says that 38 percent of incidents reported by Carbon Black partners used PowerShell.

During investigations last year, 68 percent of the company’s responding partners encountered PowerShell, and almost a third (31 percent) reported getting no security alerts before the investigation of incidents related to the scripting language.
The majority of attacks (87 percent) were clic-fraud, fake antivirus programs and ransomware, but social engineering techniques are still the favorite.
"PowerShell is a very powerful tool that offers tremendous benefit for querying systems and executing commands, including on remote machines", said Ben Johnson, Carbon Black’s chief security strategist and cofounder.
"However, more recently we’re seeing bad guys exploiting it for malicious purposes it because it falls under the radar of traditional endpoint security products. This often causes tension between the IT and security professionals. PowerShell gives the bad guys a lot of power because it’s part of the native Windows operating system, which makes it difficult for security teams. On the other hand, PowerShell helps IT guys automate various tasks. The two departments need to come together and strike a balance between IT automation and security".

source
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hackers now use Microsoft OneNote attachments to spread malware tarekma7 0 626 01-24-2023 , 10:21 AM
Last Post: tarekma7
  Microsoft seizes sites used by APT15 Chinese state hackers mrtrout 0 984 12-07-2021 , 11:16 AM
Last Post: mrtrout
  Hackers exploit Microsoft MSHTML bug to steal Google, Instagram creds mrtrout 0 1,041 11-25-2021 , 02:58 PM
Last Post: mrtrout
  COVID-Related Threats, PowerShell Attacks Lead Malware Surge Mohammad.Poorya 0 975 04-15-2021 , 05:33 AM
Last Post: Mohammad.Poorya
  Microsoft says China-backed hackers are exploiting Exchange zero-days Bjyda 0 1,000 03-03-2021 , 11:39 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)