logo

Ave Maria and the Chambers of Warzone RAT

ID: 217551d1-6974-5905-ae4a-cfe08d891565

STIX ID: report--217551d1-6974-5905-ae4a-cfe08d891565

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

**Executive summary:** This blog-style technical analysis dissects a multi-stage malware campaign that leverages maldocs and PowerShell environment persistence (HKU Run and Environment keys), Base64/AES-obfuscated stages, Discord-hosted payloads, a .NET netLoader DLL that extracts a packed RunPE payload, and RunPE/unhooking techniques to spawn a Notepad process that executes a Cobalt Strike beacon (C2: organitations.com/Preserve/stat/3E8YZFXJ, 69.28.84.201). The report provides IoCs, ELK search queries, registry locations for removal, and step-by-step analyst methods for decoding and dynamic debugging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.