logo

From APT28 to RePythonNET: automating .NET malware analysis

ID: 49850a22-6472-5aa2-beff-eabf0fc7bbdb

STIX ID: report--49850a22-6472-5aa2-beff-eabf0fc7bbdb

Feed Name: Sekoia.io Blog

Threat Score
85/100

Date Published: 2026-04-16

Date Updated: 2026-04-29

Author: Sekoia TDR

...
...

This blogpost from Sekoia's TDR describes techniques for reversing .NET malware with a focused case study on APT28's use of the Covenant .NET C2 framework. It documents manual and automated approaches to identify decryption routines, extract C2 configuration, patch binaries, and scale decompilation via pythonnet, dnlib, ILSpy and an MCP service (RePythonNET), and highlights APT28 operational tactics and infection chains used in 2024–2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.