DotRunpeX is a .NET-based injector that uses process hollowing / RunPE-style injection to execute an embedded payload inside a newly created suspended process. It has been observed as a second-stage payload across dozens of campaigns and used to deliver multiple commodity malware families, including AgentTesla, AsyncRAT, Formbook, RedLine, Remcos, Vidar, Lokibot, NetWire, and QuasarRAT. Reported common delivery vectors include phishing attachments such as ISO, IMG, ZIP, and 7Z files; fake utility websites; Google Ads abuse; and trojanized software or builder lures. It was also observed in TaskLoader-related PPI/loader-as-a-service activity tied to pirated-software lures, where TaskLoader delivered DotRunpeX and CustomerLoader.
Older and newer DotRunpeX variants share traits including 64-bit .NET executables, version metadata with ProductName set to "RunpeX.Stub.Framework," use of a .NET resource named "BIDEN_HARRIS_PERFECT_ASSHOLE" to store an encrypted payload, and process hollowing behavior. The older version used simple XOR payload decryption, limited configuration, and a D/Invoke-like approach for NT API access. The newer version is heavily protected with customized KoiVM virtualization and ConfuserEx obfuscation and is described as highly configurable, with options including anti-malware disabling, anti-VM/anti-sandbox checks, persistence, payload decryption, and multiple UAC bypass methods.
A notable newer capability is BYOVD-based security evasion. DotRunpeX has been observed dropping a valid Sysinternals Process Explorer driver, procexp.sys v16.43, to C:\Users<user>\AppData\Local\Temp\Иисус.sys, loading it via NtLoadDriver using the service key \Registry\Machine\System\CurrentControlSet\Services\TaskKill, enumerating handles with NtQuerySystemInformation, and using DeviceIoControl with IOCTL 2201288708 to close handles and terminate protected anti-malware processes, including PPL-protected processes. After disabling targeted security processes, it performs process hollowing into C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe using CreateProcessW and NtWriteVirtualMemory.
High-confidence indicators and artifacts mentioned in the content include the malware name/alias DotRunpeX, ProductName "RunpeX.Stub.Framework," resource name "BIDEN_HARRIS_PERFECT_ASSHOLE," dropped driver path ending in "Иисус.sys," abuse of procexp.sys v16.43, service key "TaskKill," and observed use in a campaign where DotRunpeX injected RedLine with C2 77.73.134.2. The content also notes possible Russian-language influence based on the driver filename "Иисус.sys."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
“DotRunpeX file to inject the malware into processes… it will then inject itself into another process using the injection technique RunPE… VirtualAllocEx and WriteProcessMemory… SetThreadContext… ResumeThread”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET process injection tool used to inject payloads into other processes; described using UAC bypass techniques and BYOVD (including use of Zemana.sys) to terminate protected/EDR processes.
A .NET-based process-hollowing injector used as a second-stage payload to decrypt and inject an embedded malware payload into a target process. Newer variants are protected with a customized KoiVM virtualizer and ConfuserEx, and can disable security by abusing a vulnerable Sysinternals Process Explorer driver (procexp v16.43) to kill protected anti-malware services (PPL) via handle-closing IOCTLs, then proceed with injection (e.g., into InstallUtil.exe).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.