Uploaded August 2025 | Updated September 2026, 10 hours ago
Unmasking MSC Files: A Deep Dive into APT Weaponization, Grim Resource Injection, and AppDomain Manager Hijacking
Hossein Jazi (Fortinet, CA), Douglas Santos (Fortinet, CA)
Hossein Jazi is a senior threat intelligence specialist at Fortinet, where he contributes as an active researcher with interests in APT tracking, malware analysis, cyber threat intelligence, and machine learning. His current efforts are centred on identifying and monitoring APT activities, along with publishing insightful blogs on their operations. In addition to these projects, Jazi is focused on developing proactive techniques to monitor cyber threat actors' actions and collaborating with various partners to enhance cyber threat research capabilities. He holds a Master's degree in computer science and has over 14 years of experience specializing in cybersecurity and APT analysis.
Douglas Santos is the Director of Advanced Threat Intelligence at Fortinet, bringing over two decades of experience in the cybersecurity field. He combines deep technical expertise with strong communication and interpersonal skills, allowing him to thrive in both technical and business-oriented environments. Doug has a keen understanding of the evolving cyber threat landscape and excels at translating complex security challenges, vulnerabilities, and countermeasures into clear, actionable insights for audiences at all levels. Currently, Doug leads a team of researchers and engineers focused on advancing the state of the art in cyber threat intelligence. Their mission is to proactively identify emerging attack vectors and develop intelligence-driven defenses. As part of this effort, Doug is spearheading Fortinet’s collaboration with MITRE CTID and contributing to projects that enhance threat intelligence standards, tools, and response strategies. These advancements are being integrated across Fortinet’s ecosystem to strengthen global cybersecurity posture. With a proven track record of innovation, leadership, and effective communication, Doug continues to be a driving force in shaping the future of cybersecurity.
--
As the cyber threat landscape evolves, so do the tactics employed by advanced persistent threats (APTs). With the increasing disablement of macros in Microsoft Office, threat actors have adapted, turning to new methods for malware delivery over recent years. Since early 2022, there has been a noticeable shift away from traditional macro-based attacks toward techniques involving ISO files, HTML smuggling, LNK files, and CHM files. Among these methods, the use of Microsoft Common Console (MSC) files remains underexplored yet has emerged as a powerful tool for malware delivery and persistence in Windows environments.Although initially limited in use, MSC files began gaining significant traction among threat actors in early 2024. Kimsuky was one of the first groups to incorporate MSC files into its campaigns, leveraging various techniques to target victims. Recently, Kimsuky expanded its MSC-based attacks by using Zoom-themed lures, incorporating the legitimate Zoom application to add credibility and increase engagement. Following Kimsuky's example, other APT groups- including Mustang Panda, APT41, and APT Bitter- have adopted MSC files as part of their initial infection strategies. Some of these APTs combine novel methods like Grim Resource Injection and AppDomain Manager Hijacking to enhance the efficacy and stealth of their attacks.These attacks, which use legitimate Windows subsystems and tools to deliver malicious payloads, pose significant challenges for detection. Traditional enterprise security solutions often focus on identifying the aftermath of these techniques- such as the loading of malicious code into legitimate Windows processes- rather than the techniques themselves. Current EDR tools generally provide limited visibility into the full attack chain and tend to rely on known malicious payload signatures or newer detection methods, such as stack-based similarity hashing, to detect frameworks like Sliver, Cobalt Strike, and Metasploit.This technical deep dive will explore how APT groups are exploiting the hidden capabilities of MSC files to conduct stealthy, sophisticated attacks. We'll provide a timeline of MSC file adoption by various threat actors and examine the structure of weaponized MSC files, focusing on advanced techniques like Grim Resource Injection and AppDomain Manager Hijacking, which enable malicious code execution in .NET environments. Recent campaigns demonstrate how APTs are increasingly using these novel techniques to expand their toolsets and evade modern security controls. We'll also discuss detection challenges, showcase a demo of these methods in action, and highlight their implications for current detection mechanisms.
Unmasking MSC Files: A Deep Dive into APT Weaponization, Grim Resource Injection, and AppDomain Manager Hijacking
Hossein Jazi (Fortinet, CA), Douglas Santos (Fortinet, CA)
Hossein Jazi is a senior threat intelligence specialist at Fortinet, where he contributes as an active researcher with interests in APT tracking, malware analysis, cyber threat intelligence, and machine learning. His current efforts are centred on identifying and monitoring APT activities, along with publishing insightful blogs on their operations. In addition to these projects, Jazi is focused on developing proactive techniques to monitor cyber threat actors' actions and collaborating with various partners to enhance cyber threat research capabilities. He holds a Master's degree in computer science and has over 14 years of experience specializing in cybersecurity and APT analysis.
Douglas Santos is the Director of Advanced Threat Intelligence at Fortinet, bringing over two decades of experience in the cybersecurity field. He combines deep technical expertise with strong communication and interpersonal skills, allowing him to thrive in both technical and business-oriented environments. Doug has a keen understanding of the evolving cyber threat landscape and excels at translating complex security challenges, vulnerabilities, and countermeasures into clear, actionable insights for audiences at all levels. Currently, Doug leads a team of researchers and engineers focused on advancing the state of the art in cyber threat intelligence. Their mission is to proactively identify emerging attack vectors and develop intelligence-driven defenses. As part of this effort, Doug is spearheading Fortinet’s collaboration with MITRE CTID and contributing to projects that enhance threat intelligence standards, tools, and response strategies. These advancements are being integrated across Fortinet’s ecosystem to strengthen global cybersecurity posture. With a proven track record of innovation, leadership, and effective communication, Doug continues to be a driving force in shaping the future of cybersecurity.
--
As the cyber threat landscape evolves, so do the tactics employed by advanced persistent threats (APTs). With the increasing disablement of macros in Microsoft Office, threat actors have adapted, turning to new methods for malware delivery over recent years. Since early 2022, there has been a noticeable shift away from traditional macro-based attacks toward techniques involving ISO files, HTML smuggling, LNK files, and CHM files. Among these methods, the use of Microsoft Common Console (MSC) files remains underexplored yet has emerged as a powerful tool for malware delivery and persistence in Windows environments.Although initially limited in use, MSC files began gaining significant traction among threat actors in early 2024. Kimsuky was one of the first groups to incorporate MSC files into its campaigns, leveraging various techniques to target victims. Recently, Kimsuky expanded its MSC-based attacks by using Zoom-themed lures, incorporating the legitimate Zoom application to add credibility and increase engagement. Following Kimsuky's example, other APT groups- including Mustang Panda, APT41, and APT Bitter- have adopted MSC files as part of their initial infection strategies. Some of these APTs combine novel methods like Grim Resource Injection and AppDomain Manager Hijacking to enhance the efficacy and stealth of their attacks.These attacks, which use legitimate Windows subsystems and tools to deliver malicious payloads, pose significant challenges for detection. Traditional enterprise security solutions often focus on identifying the aftermath of these techniques- such as the loading of malicious code into legitimate Windows processes- rather than the techniques themselves. Current EDR tools generally provide limited visibility into the full attack chain and tend to rely on known malicious payload signatures or newer detection methods, such as stack-based similarity hashing, to detect frameworks like Sliver, Cobalt Strike, and Metasploit.This technical deep dive will explore how APT groups are exploiting the hidden capabilities of MSC files to conduct stealthy, sophisticated attacks. We'll provide a timeline of MSC file adoption by various threat actors and examine the structure of weaponized MSC files, focusing on advanced techniques like Grim Resource Injection and AppDomain Manager Hijacking, which enable malicious code execution in .NET environments. Recent campaigns demonstrate how APTs are increasingly using these novel techniques to expand their toolsets and evade modern security controls. We'll also discuss detection challenges, showcase a demo of these methods in action, and highlight their implications for current detection mechanisms.










