CrySome RAT: Stealthy .NET Malware Adds AV Killer, HVNC Features
ID: fa8c8d3f-b9f2-5a13-a2be-e1c912c0709d
STIX ID: report--fa8c8d3f-b9f2-5a13-a2be-e1c912c0709d
Feed Name: GBHackers
CrySome is a sophisticated .NET remote access trojan that provides long‑term, stealthy control of Windows hosts via a modular client/server architecture; it features resilient persistence (scheduled tasks, RunOnce, services, recovery‑partition injection), AV/evasion modules that terminate and disable endpoint products, credential and cookie theft from Chromium browsers, HVNC hidden desktops, keylogging, screen/audio/webcam capture, and proxy/pivot capabilities. The report includes static/dynamic analysis details, a description of the TCP C2 protocol and handler model, examples of persistence and AV neutralization techniques, and IOCs (SHA256 hashes and a domain) useful for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
