logo

New NonEuclid RAT Evades Antivirus and Encrypts Critical Files

ID: b422721f-a912-571b-83af-835165f0f4b8

STIX ID: report--b422721f-a912-571b-83af-835165f0f4b8

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2025-01-10

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

NonEuclid is a sophisticated C# Remote Access Trojan for .NET Framework 4.8 that combines advanced evasion (AV bypass, anti-VM, rootkit-like hiding), persistence (scheduled tasks, registry/service manipulation), privilege escalation (UAC bypass), credential and cryptocurrency wallet theft, and integrated ransomware that encrypts files (appending ".NonEuclid"). It is distributed via social media, underground forums, and phishing, supports remote control and lateral movement, and is increasingly observed in criminal marketplaces; mitigation recommendations include EDR deployment, threat intelligence sharing, strict privilege management, patching, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.