logo

CrySome RAT: Stealthy .NET Malware Adds AV Killer, HVNC Features

ID: fa8c8d3f-b9f2-5a13-a2be-e1c912c0709d

STIX ID: report--fa8c8d3f-b9f2-5a13-a2be-e1c912c0709d

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

CrySome is a sophisticated .NET remote access trojan that provides long‑term, stealthy control of Windows hosts via a modular client/server architecture; it features resilient persistence (scheduled tasks, RunOnce, services, recovery‑partition injection), AV/evasion modules that terminate and disable endpoint products, credential and cookie theft from Chromium browsers, HVNC hidden desktops, keylogging, screen/audio/webcam capture, and proxy/pivot capabilities. The report includes static/dynamic analysis details, a description of the TCP C2 protocol and handler model, examples of persistence and AV neutralization techniques, and IOCs (SHA256 hashes and a domain) useful for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.