{"id":112724,"date":"2025-06-26T12:46:33","date_gmt":"2025-06-26T12:46:33","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=112724"},"modified":"2025-06-26T12:46:36","modified_gmt":"2025-06-26T12:46:36","slug":"researchers-obfuscated-weaponized-net-assemblies","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/","title":{"rendered":"Researchers Obfuscated &amp; Weaponized .NET Assemblies Using MacroPack"},"content":{"rendered":"\n<p>The cybersecurity landscape has witnessed a significant evolution in malware sophistication, with threat actors increasingly leveraging legitimate programming frameworks for malicious purposes.<\/p>\n\n\n\n<p>A recent development has emerged involving the weaponization of .NET assemblies through advanced obfuscation techniques, marking a concerning trend in offensive security operations.<\/p>\n\n\n\n<p>This sophisticated approach exploits the inherent characteristics of the .NET framework, which has become the preferred language for numerous offensive security tools including Rubeus, SeatBelt, SharpDPAPI, and Certify.<\/p>\n\n\n\n<p>The emergence of this threat stems from a fundamental vulnerability in .NET&#8217;s architecture. Unlike traditional compiled executables, .NET binaries contain intermediate language code that preserves the majority of symbols from the source code, even when compiled in release mode.<\/p>\n\n\n\n<p>This characteristic, while beneficial for legitimate development purposes, creates an opportunity for both defenders to create signatures and attackers to exploit the framework&#8217;s transparency.<\/p>\n\n\n\n<p>The malware&#8217;s attack vectors span multiple delivery mechanisms, including executable transfers, Visual Basic Scripts, JavaScript implementations, HTA documents, batch scripts, and Office documents embedded with VBA macros.<\/p>\n\n\n\n<p>BallisKit researchers <a href=\"https:\/\/blog.balliskit.com\/obfuscation-and-weaponization-of-net-assemblies-using-macropack-77feb815489c\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this sophisticated obfuscation framework integrated within MacroPack Pro, which implements a comprehensive scenario called WEAPONIZE_DOTNET.<\/p>\n\n\n\n<p>The researchers documented how threat actors can systematically transform legitimate <a href=\"https:\/\/cybersecuritynews.com\/highly-obfuscated-net-sectoprat\/\" target=\"_blank\" rel=\"noreferrer noopener\">.NET<\/a> assemblies into weaponized payloads while evading traditional security detection mechanisms.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi7btGOlDnIxFwBTlnsFHhkhSkeWx6cNBbAByUYyePXmbQvqPGBZ4z0c9sc5OLUtbh-qp7WVyGj8Uj_hW10os8d8cLbvik0IbPwGaadVmTT25cePasj8Cf0NuE1GEjaJQxw1MPC2vLkVGu3oddWwRuflrmCijpUVcrubcbs56kbIMrkHo0ywWgYe1X2q5I\/s16000\/Obfuscating%20a%20.NET%20payload%20(Source%20-%20Medium).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">Obfuscating a .NET payload (Source &#8211; Medium)<\/figcaption><\/figure><\/div>\n\n\n<p>The framework&#8217;s impact extends across multiple offensive security tools, with successful testing conducted on KrbRelay, Rubeus, Mythic Apollo Implant, SeatBelt, SharpDPAPI, and SharpHound assemblies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Advanced Obfuscation Mechanisms and Evasion Techniques<\/strong><\/h2>\n\n\n\n<p>The core strength of this weaponization approach lies in its sophisticated <a href=\"https:\/\/cybersecuritynews.com\/malware-obfuscation\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation<\/a> mechanisms that systematically neutralize common detection methods.<\/p>\n\n\n\n<p>The framework employs four primary obfuscation strategies, each targeting specific aspects of .NET assembly analysis and detection.<\/p>\n\n\n\n<p>The PInvoke to DInvoke mutation represents a critical evasion technique implemented through the <code>--obfuscate-dotnet-dinvoke-mutation<\/code> option.<\/p>\n\n\n\n<p>Traditional .NET applications use PInvoke functions to import native Windows API calls, storing function and library names in cleartext within the assembly.<\/p>\n\n\n\n<p>This creates easily detectable signatures for <a href=\"https:\/\/cybersecuritynews.com\/best-security-solutions-for-marketers\/\" target=\"_blank\" rel=\"noreferrer noopener\">security solutions<\/a>. The obfuscation process converts these static imports to dynamic DInvoke calls, executed at runtime through delegates that function as obfuscated function pointers.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj7nGC9Szpq8RSffkrarKr74A8v_38LYhdu-P5djP1uWkRYvdSMJeOMD3wnuCiwELwzVGy6usu2fCUpEc4nPHNFI0mWjlLWFv6E8lIohvz7xjC7RsGwWAI1bRAnkR23V6T8fehv4oIJ4fRVPoBJW4ua2uktb7rj9QPPgrVtJW2nFVlcGPuvvzcJfd5WE5I\/s16000\/Rubeus%20(Source%20-%20Medium).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">Rubeus (Source &#8211; Medium)<\/figcaption><\/figure><\/div>\n\n\n<pre class=\"wp-block-code\"><code>echo \"Rubeus.exe\" | macro_pack.exe -G \"Rubeus_obf.exe\" --template=WEAPONIZE_DOTNET --obfuscate-dotnet-dinvoke-mutation<\/code><\/pre>\n\n\n\n<p>The reflection handling mechanism addresses a fundamental challenge in .NET obfuscation. When assemblies use reflection to access runtime information about their own structure, traditional obfuscation breaks functionality by renaming symbols.<\/p>\n\n\n\n<p>The <code>--obfuscate-dotnet-reflection-handling<\/code> option creates runtime mapping between obfuscated symbols and their original values, maintaining functionality while preserving stealth capabilities.<\/p>\n\n\n\n<p>Perhaps most significantly, the embedding technique through <code>--obfuscate-dotnet-embed<\/code> completely transforms the assembly&#8217;s appearance by creating a .NET loader that dynamically loads the obfuscated payload directly in memory.<\/p>\n\n\n\n<p>This approach ensures the malicious assembly never touches the disk, significantly complicating forensic analysis and file-based detection systems.<\/p>\n\n\n\n<p>The framework maintains compatibility across .NET framework versions from 3.5 onward, ensuring broad deployment capabilities across Windows 7 through current Windows 10 and 11 systems.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cybersecurity landscape has witnessed a significant evolution in malware sophistication, with threat actors increasingly leveraging legitimate programming frameworks for malicious purposes. A recent development has emerged involving the weaponization of .NET assemblies through advanced obfuscation techniques, marking a concerning trend in offensive security operations. This sophisticated approach exploits the inherent characteristics of the .NET [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":112726,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-112724","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Researchers Obfuscated &amp; Weaponized .NET Assemblies Using MacroPack<\/title>\n<meta name=\"description\" content=\"Threat actors now weaponize .NET assemblies using advanced obfuscation, abusing trusted tools like Rubeus &amp; Certify for stealthy attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Researchers Obfuscated &amp; Weaponized .NET Assemblies Using MacroPack\" \/>\n<meta property=\"og:description\" content=\"Threat actors now weaponize .NET assemblies using advanced obfuscation, abusing trusted tools like Rubeus &amp; Certify for stealthy attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-26T12:46:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T12:46:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Researchers Obfuscated & Weaponized .NET Assemblies Using MacroPack","description":"Threat actors now weaponize .NET assemblies using advanced obfuscation, abusing trusted tools like Rubeus & Certify for stealthy attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/","og_locale":"en_US","og_type":"article","og_title":"Researchers Obfuscated &amp; Weaponized .NET Assemblies Using MacroPack","og_description":"Threat actors now weaponize .NET assemblies using advanced obfuscation, abusing trusted tools like Rubeus & Certify for stealthy attacks.","og_url":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-06-26T12:46:33+00:00","article_modified_time":"2025-06-26T12:46:36+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"Researchers Obfuscated &amp; Weaponized .NET Assemblies Using MacroPack","datePublished":"2025-06-26T12:46:33+00:00","dateModified":"2025-06-26T12:46:36+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/"},"wordCount":494,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/","url":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/","name":"Researchers Obfuscated & Weaponized .NET Assemblies Using MacroPack","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-06-26T12:46:33+00:00","dateModified":"2025-06-26T12:46:36+00:00","description":"Threat actors now weaponize .NET assemblies using advanced obfuscation, abusing trusted tools like Rubeus & Certify for stealthy attacks.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#primaryimage","url":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Researchers Obfuscated &amp; Weaponized .NET Assemblies Using MacroPack"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFHfiwArfcaRj4v9i89PTQhDQkwrsJb5_QE4AAamoLcPtuwl_qXtpBpRSDu8WXsZARGt23-6qpMw09bYIzS4yIGA8qlfFzf-QG6NN611T4V_rI8Zeces5LEyI-D3aH-3VBLcPuqcirl2ndfgo8w4rKZT1q5nLIMmAJoWxYXSjvoLOj0keY3FugYyJMaoU\/s16000\/Researchers%20Obfuscated%20&%20Weaponized%20.NET%20Assemblies%20Using%20MacroPack.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/112724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=112724"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/112724\/revisions"}],"predecessor-version":[{"id":112725,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/112724\/revisions\/112725"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/112726"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=112724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=112724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=112724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}