Nothing but dotnet when we shoot
ID: ab72d90b-2da2-50fd-b290-0a605b22c508
STIX ID: report--ab72d90b-2da2-50fd-b290-0a605b22c508
Feed Name: Plausible Deniablility
Date Published: 2022-11-19
Date Updated: 2026-08-11
Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}
This blog-style writeup explains why C#/.NET is attractive to malware authors, covering managed vs unmanaged code, .NET features, common evasion techniques (packing, obfuscation), examples like AgentTesla, and .NET-specific reverse-engineering considerations (IL, decompilation, mixed-mode assemblies, dynamic methods). It is an educational overview intended for analysts and hunters rather than a case report of an ongoing incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
