// ThreatHuntingLabs  ·  writeup

NightShade C2 Multi-Stage Infection — Malware Analysis (Case Lab 2/2)

ThreatHuntingLabs EDR TelemetryKQL

Case Context

Part of a 2-lab Flash Hunt case on Threat Hunting Labs: NightShade C2 Multi-Stage Infection. This lab is the Malware Analysis angle (2 of 2) — moving from the host-and-network hunt in the first lab to the scripts and payload themselves.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

Static and behavioural triage of the installer chain’s script artifacts: a VBScript stager launching a PowerShell dropper, which in turn stages an obfuscated JavaScript payload run under a legitimate portable JS runtime. The runner registers with its command-and-control server and waits for tasking, all while writing nothing further to disk in executable form.

Techniques Encountered

This angle’s Lessons panel technique-tag list wasn’t captured during the investigation, so no MITRE screenshot is included here. Broadly, the analysis centred on the VBScript-to-PowerShell staging chain and the obfuscated JavaScript runner — the same underlying artifacts the Threat Hunt angle ([[nightshade-c2-multi-stage-infection-threat-hunt]] — case-level techniques listed there) mapped end-to-end from telemetry.

Prioritising Findings — Pyramid of Pain

This angle’s debrief recorded zero Pyramid of Pain findings — the panel wasn’t populated for this angle, similar to the Detection Engineering angle on the Ursnif case.

What I Practiced

Credential

Earned a Distinction (100% score) on this Flash Hunt case.

Flash Hunt Distinction badge

Verify: https://www.threathuntinglabs.com/badges/eb22ce0d-fca8-4dc0-8d71-20394cef79ff

This closes out the 2-lab NightShade case — Threat Hunt and Malware Analysis, both against the same multi-stage installer chain.