logo

Uncovering .NET Malware Obfuscated by Encryption and Virtualization

ID: ecea64d5-a4b2-5b78-ac9d-23c11d73d2a7

STIX ID: report--ecea64d5-a4b2-5b78-ac9d-23c11d73d2a7

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-03-03

Date Updated: 2026-04-28

Author: Lee Wei Yeong

...
...

This report analyzes a cluster of multi-stage .NET malware that hides Stage 2 payloads in the PE overlay and uses AES encryption (CBC/ECB), KoiVM code virtualization, and .NET reflection to decrypt and execute final payloads (mostly Agent Tesla and XWorm, with one FormBook/XLoader sample). It details the three-stage attack chain (overlay-encrypted Stage 1, virtualized Stage 2, decrypted Stage 3), highlights AMSI bypass tokens and in-memory execution techniques, provides IoCs (SHA-256 hashes, C2 endpoints, SMTP credentials) and recommends detection/mitigation approaches including debugger-based analysis and Palo Alto Networks protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.