Executive Summary
Security researchers have identified a technique where the Windows Package Manager (WinGet) is abused to execute malicious code via the Desired State Configuration (DSC) engine. By utilizing the `winget configure` command or direct COM API calls, attackers can execute PowerShell scripts embedded in YAML files (which can be renamed to common extensions like .jpg or .txt). This method allows for stealthy code execution because it avoids direct invocation of standard PowerShell processes, which are typically heavily monitored by EDR solutions.
The attack chain involves WinGet spawning the `ConfigurationRemotingServer.exe` process to implement system changes defined in DSC resources, such as `PSDscResources/Script`. A proof-of-concept tool named DSCourier demonstrates how this technique can be used for automated reverse shells and persistence (e.g., creating local administrator accounts). Since WinGet is a native tool in Windows 10, 11, and Server 2025, this represents a significant LOLBIN (Living off the Land Binary) risk.
This threat is high priority for SOC teams because it provides a path for implant staging and persistent access while appearing as legitimate administrative activity. Organizations that do not use WinGet for automated deployment should treat any occurrence of related processes and configuration loading as highly suspicious.
