MITRE ATT&CK Technique
T1127.001MSBuild
- First Reported
- Sep 8, 2025
- Latest Reported
- Oct 6, 2026
Official Description
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.(Citation: MSDN MSBuild)
Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual Basic code to be inserted into an XML project file.(Citation: MSDN MSBuild)(Citation: Microsoft MSBuild Inline Tasks 2017) MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.(Citation: LOLBAS Msbuild)
Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual Basic code to be inserted into an XML project file.(Citation: MSDN MSBuild)(Citation: Microsoft MSBuild Inline Tasks 2017) MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.(Citation: LOLBAS Msbuild)
- Tactics
- Stealth, Execution
- Platforms
- Windows
- Parent Technique
- T1127 · Trusted Developer Utilities Proxy Execution
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026
Reported Context (2)
- A custom GetFrameworkPaths target in the malicious .csproj file caused the project's design-time build to copy and launch malware. Iranian-Aligned Blinder Tunnel Campaign Targets Iraqi Critical Infrastructure
- The SectopRAT execution chain injected malware into MSBuild.exe. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
Malware (13)
People (4)
Threat Actors (4)
MITRE ATT&CK (39)
Vendors (7)
Products (18)
Tools (10)
Industries (3)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.