confidencehighupdated2026-08-12

wscript-powershell-cradle

Multi-stage execution chain: JScript/WScript carrier instantiates WScript.Shell (or Shell.Application), expands environment variables, and spawns powershell.exe with -ExecutionPolicy Bypass and -WindowStyle Hidden to execute a PowerShell payload in a hidden window. The PowerShell stage is typically a download cradle, reflective .NET loader, or inline encoded command.

Why it works. Parent-child telemetry shows wscript.exe → powershell.exe, but the PowerShell command line is often assembled from obfuscated string fragments at runtime, defeating static command-line signatures. The use of -EncodedCommand or environment-variable staging further separates the payload from the carrier.

Variations observed.

  • Direct WshShell.Run("powershell -ep bypass ...")
  • Environment-variable staging: WScript writes payload to %TEMP% env var, PowerShell reads it.
  • WMI hidden spawn (Win32_Process.Create with ShowWindow = 0) to avoid WScript.Shell.Run telemetry.

Observed in

  • unclassified-js-german-locale-dropper (d3d22298) — bracket-notation COM API assembly + PowerShell C2 cradle.
  • Sample 6f4de3f9 — deobfuscated strings show powershell, -NoProfile, -WindowStyle Hidden, and Add-Content fragments, consistent with a WScript → PowerShell → payload chain. ^[/intel/analyses/6f4de3f972e1acf8ca603ff87b65ab4b92abf303f98b87cc7e822bfd5828d132.html]
  • 37e8fc3692a6 (Payment-Swift-TT05294758.js) — WScript → MSXML2.XMLHTTP download → powershell.exe -nop -ep bypass -windowstyle hidden -file execution chain, part of the itegroup-sbs-dropper cluster. ^[/intel/analyses/37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2.html]