PowerShell threats surge: 95.4% of analysed scripts were malicious
Symantec is warning of a rise in malicious PowerShell scripts, as attackers increasingly use the framework's flexibility to download payloads, traverse through a compromised network and carry out reconnaissance.
Symantec analysed 111 PowerShell malware samples to find out how much of a danger they posed. Of all of the PowerShell scripts analysed by Symantec, 95.4 percent were malicious. “This shows that externally sourced PowerShell scripts are a major threat to enterprises,” the company said.
“We have predominantly seen malicious PowerShell scripts used as downloaders, such as Office macros, and during the lateral movement phase, where a threat executes code on a remote computer when spreading inside the network.”
