Overview
The payload lives in the registry, PowerShell or WMI and is re-hydrated on every boot, so static file scanning has nothing to look at.\nThe trick is living off the land: cmd, certutil, mshta and rundll32 do the work, all signed by the vendor.\nDetection shifts to behavioural telemetry, script-block logging and command-line auditing.
Indicators of Compromise
Signals that suggest this is present on a system.
- Encoded PowerShell launched from Office documents
- WMI permanent event subscriptions
- Registry values containing script payloads
Controls that stop it
-
Keep Tested, Offline Backups
Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.