logo

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

ID: c08d8fdb-4456-5cf6-9321-53ac9782e5bf

STIX ID: report--c08d8fdb-4456-5cf6-9321-53ac9782e5bf

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: Sean Shirley and Kyle Sopt

...
...

This report details a targeted spear-phishing campaign that used a fake logistics rate confirmation to deliver a multi-stage infection chain culminating in CrySome RAT; the chain leverages living-off-the-land execution, a UAC bypass, in-memory AMSI patching, and an open-source Defender disruption tool (WinDefCtl) to achieve persistence, HVNC/remote command execution, credential theft from Chromium browsers, and broad AV/EDR interference, and it provides IOCs and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.