Living off the land

Attackers increasingly use the administrative tools already installed and already trusted.

Scripting engines, remote management utilities, archive tools, the things every system has. There is no malicious file to detect, no unusual binary, nothing for a signature to match. Detection has to shift to how the tools are being used and by whom, which is a much harder question than what is this file.

Checked against the primary source.

More on Malware & ransomware