<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://tcwiki.azurewebsites.net/index.php?action=history&amp;feed=atom&amp;title=Powershell</id>
		<title>Powershell - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://tcwiki.azurewebsites.net/index.php?action=history&amp;feed=atom&amp;title=Powershell"/>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Powershell&amp;action=history"/>
		<updated>2026-09-12T06:18:41Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Powershell&amp;diff=22885&amp;oldid=prev</id>
		<title>Tom: /* Problems= */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Powershell&amp;diff=22885&amp;oldid=prev"/>
				<updated>2025-02-14T01:43:40Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Problems=&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 01:43, 14 February 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l2&quot; &gt;Line 2:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 2:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A scripting language that allows the execution of an .NET method from the command line.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A scripting language that allows the execution of an .NET method from the command line.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Problems&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;=&lt;/del&gt;==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Problems==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===North Korean Exploit===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===North Korean Exploit===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;2025-02-13 Microsoft Threat Intelligence has observed North Korean state actor Emerald Sleet (also known as Kimsuky and VELVET CHOLLIMA) using a new tactic in targeted attacks: tricking targets into running PowerShell as an administrator and then pasting and running code provided by the threat actor. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;2025-02-13 Microsoft Threat Intelligence has observed North Korean state actor Emerald Sleet (also known as Kimsuky and VELVET CHOLLIMA) using a new tactic in targeted attacks: tricking targets into running PowerShell as an administrator and then pasting and running code provided by the threat actor. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Powershell&amp;diff=22884&amp;oldid=prev</id>
		<title>Tom: Created page with &quot;==Full Title or Meme== A scripting language that allows the execution of an .NET method from the command line.  ==Problems=== ===North Korean Exploit=== 2025-02-13 Microsoft T...&quot;</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Powershell&amp;diff=22884&amp;oldid=prev"/>
				<updated>2025-02-14T01:41:41Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;==Full Title or Meme== A scripting language that allows the execution of an .NET method from the command line.  ==Problems=== ===North Korean Exploit=== 2025-02-13 Microsoft T...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Full Title or Meme==&lt;br /&gt;
A scripting language that allows the execution of an .NET method from the command line.&lt;br /&gt;
&lt;br /&gt;
==Problems===&lt;br /&gt;
===North Korean Exploit===&lt;br /&gt;
2025-02-13 Microsoft Threat Intelligence has observed North Korean state actor Emerald Sleet (also known as Kimsuky and VELVET CHOLLIMA) using a new tactic in targeted attacks: tricking targets into running PowerShell as an administrator and then pasting and running code provided by the threat actor. &lt;br /&gt;
&lt;br /&gt;
To execute this tactic, the threat actor masquerades as a South Korean government official and over time builds rapport with a target before sending a spear-phishing email. To read the PDF file attached to the email, the target is lured to click a URL with instructions to register their device. The registration link has instructions to open PowerShell as an administrator and paste code provided by Emerald Sleet. If the target runs the code as an administrator, the code downloads and installs a browser-based remote desktop tool, downloads a certificate file with a hardcoded PIN from a remote server, and then sends a web request to a remote server to register the victim device using the downloaded certificate and PIN. This allows the threat actor to access the device and carry out data exfiltration. &lt;br /&gt;
&lt;br /&gt;
While we have only observed the threat actor using this tactic in limited attacks since January 2025, this shift is indicative of a new approach to compromising their traditional espionage targets. Emerald Sleet is known to primarily target individuals working in international affairs, with a special focus on those whose work relates to Northeast Asia, as well as non-government organizations, government agencies and services, and media in North America, South America, Europe, and East Asia. &lt;br /&gt;
&lt;br /&gt;
Microsoft directly notifies customers who have been targeted or compromised by nation-state actor activity, providing them with the necessary information to secure their accounts. Microsoft Defender XDR detects this Emerald Sleet activity. In addition to investing in advanced anti-phishing solutions, Microsoft recommends training end-users about phishing and the dangers of clicking URLs in unsolicited messages and employing attack surface reduction rules to prevent common attack techniques like using malicious scripts.&lt;br /&gt;
&lt;br /&gt;
==References==&lt;/div&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	</feed>