logo

New .NET AOT Malware Hides Code as a Black Box to Evade Detection

ID: c10ef9e6-fe59-5f4b-8e5f-e30419b76a17

STIX ID: report--c10ef9e6-fe59-5f4b-8e5f-e30419b76a17

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Howler Cell researchers uncovered a multi-stage .NET Ahead-of-Time (AOT) malware campaign spread via phishing ZIPs: KeyAuth.exe downloads bound_build.exe which XOR-decrypts and launches two payloads — Crypted_build.exe (delivering the Rhadamanthys infostealer) and Miner.exe (installing MicrosoftEdgeUpdater, a loader for XMRig). The attackers use AOT compilation to remove metadata and a scoring-based sandbox-evasion check (RAM, uptime, document file count, AV processes) to avoid analysis; analysts recovered functionality using Binary Ninja and a custom WARP signature. Users are advised to avoid untrusted ZIPs and keep systems updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.