New .NET AOT Malware Hides Code as a Black Box to Evade Detection
ID: c10ef9e6-fe59-5f4b-8e5f-e30419b76a17
STIX ID: report--c10ef9e6-fe59-5f4b-8e5f-e30419b76a17
Feed Name: HackRead
Howler Cell researchers uncovered a multi-stage .NET Ahead-of-Time (AOT) malware campaign spread via phishing ZIPs: KeyAuth.exe downloads bound_build.exe which XOR-decrypts and launches two payloads — Crypted_build.exe (delivering the Rhadamanthys infostealer) and Miner.exe (installing MicrosoftEdgeUpdater, a loader for XMRig). The attackers use AOT compilation to remove metadata and a scoring-based sandbox-evasion check (RAM, uptime, document file count, AV processes) to avoid analysis; analysts recovered functionality using Binary Ninja and a custom WARP signature. Users are advised to avoid untrusted ZIPs and keep systems updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
