CactusTorch is using DotNetToJScript to execute harmful.NET assemblies from memory. Researchers at McAfee Labs reported that they compiled the tool and uncovered the.NET executable DotNet toJScript. The.NET assembly is responsible for creating a new. process, allocating memory, writing shellcode in the targets memory process and creating a thread to execute the shellcode. The script host (wscript.exe) executes the JavaScript file on a target system.”]

