The best hiding place is often a binary Microsoft already signed. This talk presents a complete red team operation reconstructed from a real multi-stage JScript dropper captured in April 2026 targeting Energy, Government, and Aerospace organizations. Using custom tooling and malware analysis, we transformed the adversary's workflow into a repeatable offensive playbook focused on trusted binary abuse, fileless execution, and stealthy process injection.
The session demonstrates how attackers delivered a .NET payload through steganographic C2 hosted on trusted paste services, loaded assemblies directly in memory with Reflection.Assembly::Load(), and performed Process Hollowing into msbuild.exe using native Windows APIs including ZwUnmapViewOfSection, VirtualAllocEx, and SetThreadContext.
We also explore operational evasion techniques such as WMI hidden process spawning, obfuscated Base64 transformations, and Sysmon telemetry analysis from the perspective of a red team operator. Every technique shown was extracted from a live adversary sample and operationalized for realistic adversary emulation.
Presented at La Villa Hacker — DEF CON 2026