CSharp-Streamer-RAT is a remote access trojan observed as a follow-on payload in intrusion chains associated with TA866 (also known as Asylum Ambuscade). Cisco Talos reported that it was selectively deployed after initial access and staging activity involving malware such as WarmCookie/BadSpace, and in early 2024 observed WarmCookie infections followed by deployment of CSharp-Streamer-RAT and Cobalt Strike. The malware is used to provide post-compromise remote access and has been referenced in intrusion activity for credential theft and exfiltration of sensitive data, including use alongside Rclone. Talos attributed a 2023 intrusion using CSharp-Streamer-RAT C2 server 109[.]236[.]80[.]191 to TA866, and prior reporting linked that same server to activity associated with IcedID and ALPHV ransomware. Reported C2 infrastructure includes 185[.]73[.]124[.]164 and 109[.]236[.]80[.]191; Talos also identified additional C2 servers whose SSL certificates appeared to be generated using the same threat actor-defined algorithm. The malware has been observed in campaigns affecting primarily organizations in the United States, with additional cases in Canada, the United Kingdom, Germany, Italy, Austria, and the Netherlands; manufacturing was the most affected sector, followed by government and financial services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we observed a case in early 2024 where Cobalt Strike and CSharp-Streamer-RAT were deployed as follow-on payloads following the initial WarmCookie infection.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan (RAT) observed as a follow-on payload deployed after WarmCookie infections to maintain control of compromised systems.
CSharp-Streamer-RAT is referenced as a secondary payload delivered by WarmCookie.
CSharp-Streamer-RAT is a remote access trojan deployed as a follow-on payload in TA866 and WarmCookie-linked intrusions. Its C2 infrastructure shared SSL certificate generation characteristics across related campaigns.
RAT mentionné comme charge tierce déployée par WarmCookie.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.