From APT28 to RePythonNET: automating .NET malware analysis
ID: 86c6eebc-9ab5-5b5c-b490-538567fafd23
STIX ID: report--86c6eebc-9ab5-5b5c-b490-538567fafd23
Feed Name: Sekoia.com
Threat Score
This blogpost describes a methodology and tooling (RePythonNET-MCP) to automate .NET malware analysis using pythonnet, dnlib, and ILSpy, demonstrating automated string decryption, decompilation, and AI-assisted renaming on an APT28-linked Covenant sample; it also details APT28 operational TTPs including Signal-delivered lure documents, COM hijack persistence, steganographic shellcode delivery, Covenant Grunt usage, and fallback implants like BeardShell and SlimAgent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
