Brunswick, ME • (207) 245-1010 • contact@johnzblack.com
MSBuild is a Microsoft-signed Windows binary. SHADOW#REACTOR chains VBScript to PowerShell to a payload disguised as plain text. Both campaigns share one design principle: look like the environment, not like malware. Multiple independent threat actors are converging on the same technique, and most defenders aren't ready for it.
Read More