FYAnti is a Windows malware component associated with menuPass, also known as APT10, and is also tracked as DILLJUICE Stage 2. It functions as an in-memory intermediary stage in a multi-layer intrusion chain in which SigLoader loads FYAnti, after which FYAnti decrypts an embedded .NET module and reflectively executes it using the CppHostCLR technique. This approach enables execution of .NET code inside a native process without writing the assembly to disk, making the malware notably fileless and complicating host-based detection and forensic recovery.
FYAnti has been observed using ConfuserEx to pack its .NET module as an additional defense-evasion measure. Its primary role is to unpack, decrypt, and launch subsequent payload logic in memory; in documented activity, it has been used to load QuasarRAT. The malware is part of tradecraft used in espionage operations attributed to APT10/menuPass, a threat actor known for targeting sectors including healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government. FYAnti is best characterized as a stealthy loader stage focused on decryption and reflective in-memory execution of downstream .NET payloads on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Eventually, SigLoader will load the first payload, FYAnti, in memory. FYAnti decrypts the first embedded .NET module and reflectively loads executing the module using the CppHostCLR technique to avoid dropping additional files to disk.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
The malware makes use of CppHostCLR due its ability to inject and execute the .NET loader assembly without extraction to disk.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A memory-resident loader used by menuPass that decrypts an embedded .NET module and reflectively loads it via CppHostCLR to avoid disk artifacts.
Enterprise New Software: ... FYAnti
Malware that decrypts an embedded .NET module.
Stage-2 component that loads QuasarRAT in the described campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.