From Phishing to Persistence: A CrySome RAT Infection Chain Analysis
ID: c08d8fdb-4456-5cf6-9321-53ac9782e5bf
STIX ID: report--c08d8fdb-4456-5cf6-9321-53ac9782e5bf
Feed Name: LevelBlue SpiderLabs Blog
This report details a targeted spear-phishing campaign that used a fake logistics rate confirmation to deliver a multi-stage infection chain culminating in CrySome RAT; the chain leverages living-off-the-land execution, a UAC bypass, in-memory AMSI patching, and an open-source Defender disruption tool (WinDefCtl) to achieve persistence, HVNC/remote command execution, credential theft from Chromium browsers, and broad AV/EDR interference, and it provides IOCs and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
