Post
Microsoft Threat Intelligence
threatintel.microsoft.com
did:plc:ezrjx3qddwj4azn373c2ipdg
A later PowerShell stage downloads the next-stage payload as cab.dat, then reads and executes its contents in a hidden window. The PowerShell stage triggers .NET compilation using csc.exe and cvtres.exe, then launches timeout.exe.
2026-10-03T01:48:51.907Z