Ave Maria and the Chambers of Warzone RAT
ID: 217551d1-6974-5905-ae4a-cfe08d891565
STIX ID: report--217551d1-6974-5905-ae4a-cfe08d891565
Feed Name: Huntress Blog
**Executive summary:** This blog-style technical analysis dissects a multi-stage malware campaign that leverages maldocs and PowerShell environment persistence (HKU Run and Environment keys), Base64/AES-obfuscated stages, Discord-hosted payloads, a .NET netLoader DLL that extracts a packed RunPE payload, and RunPE/unhooking techniques to spawn a Notepad process that executes a Cobalt Strike beacon (C2: organitations.com/Preserve/stat/3E8YZFXJ, 69.28.84.201). The report provides IoCs, ELK search queries, registry locations for removal, and step-by-step analyst methods for decoding and dynamic debugging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
