Microsoft Deprecates VBScript
learn.microsoft.com
learn.microsoft.com
Powershell can be configured to prevent those attack vectors.
Also hardly any different from people doing "curl | sudo sh" to install random stuff.
I love how a lot of Linux users go and make fun of windows security, but 90% of tutorials go around throwing sudos commands "because why not", with some of them even curling sh files from servers with weird domains.
And the weirdest thing? 99.999% of the time there is not malware involved... but it totally could. It reminds me of those towns where people go to work without locking their doors. It's beautiful and sketchy at the same time.
Totally.
Otherwise there are also settings that allow locally created files but block downloaded powershell files using NTFS alternate data stream tags.
The first thing the PS script did was to add Windows Defender exceptions to hide itself. And it worked beautifully. All the rest of the downloading, decrypting, and making the scheduled task to start Redline at user login succeeded.
The only tipoff was seeing Powershell.exe in task manager with a base64 encoded command line argument. Any sufficiently advanced system administration tool is also powerful enough for a worm. The whole experience reminds me a lot of those early worms in the 2000s.
A running application should not, by default, have access to everything on disk (and every program running on the PC too). You will never annihalate every attack vector, especially when the limiting factor is dumb users.