AssemblyExecuter is a .NET in-memory loader within the NET-STAR malware suite documented by Palo Alto Networks Unit 42. NET-STAR targets IIS web servers and has been associated with the China-aligned espionage actor Phantom Taurus. The suite includes IIServerCore and two AssemblyExecuter variants, v1 and v2. Both AssemblyExecuter versions are used to execute arbitrary .NET assemblies directly in memory via Assembly.Load() without writing them to disk. AssemblyExecuter v2 adds AMSI and ETW bypass capabilities and can select bypass techniques based on input parameters. NET-STAR is described as web-based malware used against IIS environments, with IIServerCore loaded by an ASPX web shell named OutlookEN.aspx and operating filelessly inside the IIS worker process w3wp.exe. Unit 42 reported Phantom Taurus targeting government and telecommunications organizations across Africa, the Middle East, and Asia, with espionage objectives focused on ministries of foreign affairs, embassies, diplomatic communications, defense-related intelligence, geopolitical events, and military operations. Related NET-STAR tradecraft includes encrypted AES-based command-and-control, cookie-based session handling, in-memory execution, and anti-forensics such as timestomping. Reported SHA-256 indicators for ExecuteAssembly.dll variants associated with AssemblyExecuter are 3e55bf8ecaeec65871e6fca4cb2d4ff2586f83a20c12977858348492d2d0dec4, afcb6289a4ef48bf23bab16c0266f765fab8353d5e1b673bd6e39b315f83676e, and b76e243cf1886bd0e2357cbc7e1d2812c2c0ecc5068e61d681e0d5cff5b8e038.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Two New Variants of .NET Malware Loaders... we named AssemblyExecuter... v1... used around 2024... v2... used in 2025... executing other .NET assemblies directly in memory... v2 includes... bypassing... AMSI and ETW."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Two-version .NET in-memory loader used to execute arbitrary .NET assemblies without writing to disk (via Assembly.Load and invoking entry point). v2 adds selectable AMSI and ETW bypass routines to operate under higher monitoring/detection pressure.
.NET in-memory loader used to execute arbitrary .NET assemblies without writing to disk. v2 adds selective AMSI and ETW bypass methods to reduce detection in monitored environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.