MSBuild

T1127.001

Sub-technique of T1127 Trusted Developer Utilities Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.

Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual Basic code to be inserted into an XML project file. MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.

Detection rules5

Rules on DetectionCode tagged with T1127.001.

Sigma1

RuleLevelLog source
Silenttrinity Stager Msbuild Activityhighwindows / network_connection

Splunk4

RuleTypeRiskData source
MSBuild Suspicious Spawned By Script ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious msbuild pathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious MSBuild RenameHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious MSBuild SpawnTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software3

Campaigns2

Procedure examples5

Software3

Used byProcedure example
ToolEmpire

Empire can use built-in modules to abuse trusted utilities like MSBuild.exe.

MalwareNOOPLDR

NOOPLDR can be executed via MSBuild.

MalwarePlugX

A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques.

Campaigns2

Used byProcedure example
CampaignFrankenstein

During Frankenstein, the threat actors used MSbuild to execute an actor-created file.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool.

References3

  1. LOLBAS Msbuild Open source
    LOLBAS. (n.d.). Msbuild.exe. Retrieved July 31, 2019.
  2. MSDN MSBuild Open source
    Microsoft. (n.d.). MSBuild1. Retrieved November 30, 2016.
  3. Microsoft MSBuild Inline Tasks 2017 Open source
    Microsoft. (2017, September 21). MSBuild inline tasks. Retrieved March 5, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.