logo

The Intel “AppDomain” Hijack: Unmasking a Sophisticated Post-Exploitation Framework

ID: 074dd57c-93b8-5cf5-b527-bb8d271624cf

STIX ID: report--074dd57c-93b8-5cf5-b527-bb8d271624cf

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

CYFIRMA reports a sophisticated multi-stage post-exploitation framework targeting financial organizations in the Middle East and EMEA that hijacks the .NET AppDomain Manager to weaponize a signed Intel utility (IAStorHelp.exe), enabling stealthy in-memory execution via JIT-based trampolining, extensive obfuscation, sandbox-evasion delays, and CloudFront domain-fronted C2, representing a high-risk, resilient toolset comparable to mature offensive platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.