NTT Security Japan reported a malware campaign that used malicious Microsoft Management Console (.msc) files and AppDomainManager Injection to execute payloads with minimal user interaction. Since around July 2024, attackers distributed ZIP archives through spear-phishing emails and attacker-controlled websites, then abused the GrimResource technique so that opening an MSC file could trigger embedded JavaScript via apds.dll, execute VBScript, download additional files, and launch a renamed legitimate Microsoft binary, oncesvc.exe.
The attack chain relied on a companion configuration file that abused .NET version redirection to load a malicious DLL derived from AppDomainManager, culminating in deployment of a Cobalt Strike beacon. Researchers said the tooling and infrastructure resembled APT41, with likely targeting that included Taiwanese government organizations, the Philippine army, and Vietnam’s energy sector. Separate public research from Elastic and offensive-security writeups from Rapid7 and Pentest Laboratories show that AppDomainManager Injection is an established technique that can be easier to abuse and harder to detect than traditional DLL side-loading, raising concern that its use may spread.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
NTT Security Japan assessed the loader and infrastructure used in the campaign as similar to APT41. The report also suggested likely targeting of Taiwanese government organizations, the Philippine army, and Vietnam's energy sector.
In the observed intrusions, opening the MSC file triggered GrimResource-based code execution through apds.dll, which led to VBScript downloading files and launching a renamed Microsoft-signed binary with a malicious AppDomainManager-derived DLL. The attackers ultimately deployed a Cobalt Strike beacon on victim systems.
NTT Security Japan reported that attacks abusing AppDomainManager Injection had been observed since around July 2024. The campaign used malicious MSC files delivered in ZIP archives from attacker-controlled websites or spear-phishing emails.
Rapid7 published research on new AppDomain Manager Injection techniques for red teams, further documenting offensive use of the method.
A public write-up described AppDomainManager Injection and detection considerations, establishing the technique as a known method for loading malicious .NET code through legitimate processes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
jp.security.ntt
Open sourceelastic.co
Open sourcepentestlaboratories.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.