The Intel “AppDomain” Hijack: Unmasking a Sophisticated Post-Exploitation Framework
ID: 074dd57c-93b8-5cf5-b527-bb8d271624cf
STIX ID: report--074dd57c-93b8-5cf5-b527-bb8d271624cf
Feed Name: securityonline.info
Threat Score
CYFIRMA reports a sophisticated multi-stage post-exploitation framework targeting financial organizations in the Middle East and EMEA that hijacks the .NET AppDomain Manager to weaponize a signed Intel utility (IAStorHelp.exe), enabling stealthy in-memory execution via JIT-based trampolining, extensive obfuscation, sandbox-evasion delays, and CloudFront domain-fronted C2, representing a high-risk, resilient toolset comparable to mature offensive platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
