Bitdefender Finds 84% of Attacks Use Built In Windows Tools, Here’s How
Criminal groups have increasingly adopted the tactic of utilizing pre-installed software on Windows computers for malicious activities, a method known as "Living off the Land." Bitdefender Labs conducted an analysis of 700,000 incidents through its…
Criminal groups have increasingly adopted the tactic of utilizing pre-installed software on Windows computers for malicious activities, a method known as "Living off the Land." Bitdefender Labs conducted an analysis of 700,000 incidents through its GravityZone platform, revealing that 84% of high-severity breaches employed this strategy. A similar review showed an 85% occurrence in their managed detection operations.
These tools, signed by Microsoft, perform legitimate tasks such as scripting and firewall updates, making them initially undetectable by security scanners. As a result, attackers can navigate systems undetected, appearing as routine maintenance while collecting data.
Netsh.exe , used to modify network configurations, was identified in one-third of the serious breaches. While essential for firewall management, its misuse poses security risks. PowerShell is also frequently exploited, with 96% of organizations using it for legitimate purposes and 73% of endpoints activating it occasionally. Third-party applications often utilize hidden PowerShell windows, providing additional cover for intruders.
A similar review showed an 85% occurrence in their managed detection operations.
Other tools such as reg.exe , rundll32.exe , and the C# compiler csc.exe are also exploited. Additionally, msbuild.exe and ngen.exe , typically used by software developers, are targeted in attack sequences, indicating the comprehensive search by attackers for exploitable programs.
Regional Variations in PowerShell Usage
Bitdefender observed regional differences in PowerShell usage. In the Asia-Pacific region, 53.3% of organizations recorded PowerShell activity, significantly lower than the 97.3% observed in Europe, the Middle East, and Africa. In regions with less PowerShell activity, attackers exploit reg.exe more frequently. Legacy tools like WMIC remain in use due to legacy software dependencies, enabling attackers to blend malicious activities with routine system checks.
Bitdefender developed GravityZone Proactive Hardening and Attack Surface Reduction (PHASR) to monitor and mitigate malicious activities without disrupting legitimate operations. By analyzing typical behavior, PHASR identifies and halts suspicious actions, such as PowerShell scripts using encrypted text or attempting to disable protections, while allowing harmless scripts to proceed. This proactive approach also includes monitoring tools like WMIC and netsh.
Based on reporting by techround.co.uk.
