logo

From APT28 to RePythonNET: automating .NET malware analysis

ID: 86c6eebc-9ab5-5b5c-b490-538567fafd23

STIX ID: report--86c6eebc-9ab5-5b5c-b490-538567fafd23

Feed Name: Sekoia.com

Threat Score
85/100

Date Published: 2026-04-16

Date Updated: 2026-07-20

...
...

This blogpost describes a methodology and tooling (RePythonNET-MCP) to automate .NET malware analysis using pythonnet, dnlib, and ILSpy, demonstrating automated string decryption, decompilation, and AI-assisted renaming on an APT28-linked Covenant sample; it also details APT28 operational TTPs including Signal-delivered lure documents, COM hijack persistence, steganographic shellcode delivery, Covenant Grunt usage, and fallback implants like BeardShell and SlimAgent.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.