backdoorLnkMacroStagerObfuscated. Obfuscated Powershell Empire 2.x stager that allows for creation of a macro which uses VBA to backdoor .lnk files on the system. This is done to obtain a shell via follow-up user interaction natively through powershell, in order to evade tools that monitor process execution. Backdoors are self-cleaning on execution.

github.com/G0ldenGunSec/backdoorLnkMacroStagerObfuscated

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.