WinGet DSC Arbitrary Code Execution and DSCourier Malware
Score: 9/10

WinGet DSC Arbitrary Code Execution and DSCourier Malware

Threat actors can abuse the Microsoft WinGet configure command and COM APIs to execute arbitrary PowerShell scripts via YAML files, bypassing standard process monitoring.

Executive Summary

Security researchers have identified a technique where the Windows Package Manager (WinGet) is abused to execute malicious code via the Desired State Configuration (DSC) engine. By utilizing the `winget configure` command or direct COM API calls, attackers can execute PowerShell scripts embedded in YAML files (which can be renamed to common extensions like .jpg or .txt). This method allows for stealthy code execution because it avoids direct invocation of standard PowerShell processes, which are typically heavily monitored by EDR solutions.

The attack chain involves WinGet spawning the `ConfigurationRemotingServer.exe` process to implement system changes defined in DSC resources, such as `PSDscResources/Script`. A proof-of-concept tool named DSCourier demonstrates how this technique can be used for automated reverse shells and persistence (e.g., creating local administrator accounts). Since WinGet is a native tool in Windows 10, 11, and Server 2025, this represents a significant LOLBIN (Living off the Land Binary) risk.

This threat is high priority for SOC teams because it provides a path for implant staging and persistent access while appearing as legitimate administrative activity. Organizations that do not use WinGet for automated deployment should treat any occurrence of related processes and configuration loading as highly suspicious.

Key Details

Threat Name

WinGet DSC Arbitrary Code Execution

Affects

—

Adversary

—

Malware/Tools

DSCourier

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details9
Detection Guidance9
Enterprise Relevance9
Clarity & Structure10
Technical Depth8

Sources