CrySome RAT Emerges as Advanced .NET Malware With AV Killer and HVNC Capabilities
ID: 9e53b12f-e6ab-5567-af32-6fb8b1c869ac
STIX ID: report--9e53b12f-e6ab-5567-af32-6fb8b1c869ac
Feed Name: cybersecurityNews.com
CrySome RAT is a sophisticated C# remote access trojan that achieves extreme persistence by copying itself into the Windows recovery partition and modifying offline registry hives to survive factory resets. It features a modular design with a TCP-based C2 (noted domain crysome.net), an AVKiller module that targets and neutralizes major endpoint products, an HVNC invisible desktop capability, credential harvesting, keylogging, webcam and screen capture, and SOCKS proxy support for lateral movement; recommended responses include isolating affected hosts, blocking related domains, enabling tamper protection, inspecting recovery partitions/offline registries, enforcing application control, and maintaining offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
