Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
...a multi-layered persistence design composed of registry startup entries, scheduled tasks...
In this incident, the RAT created a scheduled task that relaunched the client every few minutes.
Supported actions include hidden virtual desktops, keylogging, proxying, and remote command execution.
...a multi-layered persistence design composed of registry startup entries, scheduled tasks...
In this incident, the RAT created a scheduled task that relaunched the client every few minutes.
It closes the browser, injects a helper DLL, and reads saved passwords and cookies.
CrySome RAT represents a modular, userland-focused post-exploitation framework emphasizing persistence, evasion, and operator control(Keylogger, Credential harvesting, RDP, HVNC).
Supported actions include hidden virtual desktops, keylogging, proxying, and remote command execution.
It speaks to its command-and-control server over a plain TCP channel. On connect, it sends a host profile that includes the username, OS, and the active window title.
Supported actions include hidden virtual desktops, keylogging, proxying, and remote command execution.
Once AMSI protections have been bypassed, the loader downloads stage.ps1 from the attacker-controlled infrastructure and immediately executes it in memory using IEX
Once host defenses were weakened, CrySome RAT established persistent remote access to the compromised system. The malware provided the operator with capabilities including hidden virtual network computing (hVNC), remote command execution (RCE), system reconnaissance, and credential theft.
After that, the loader patched AMSI in memory so PowerShell scanning stopped. Then a second-stage script added Microsoft Defender exclusions and pulled down more files.
followed by an in-memory Antimalware Scan Interface (AMSI) patch that bypassed AMSI scanning for subsequent PowerShell execution... the actor then targeted host defenses by executing WinDefCtl... leveraging Image File Execution Options (IFEO) manipulation and a kernel driver ( kvckiller.sys ) to interfere with Microsoft Defender components
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular C#/.NET remote access trojan delivered via spear-phishing that enables hidden remote control, UAC bypass support, AMSI patching, Defender tampering, hVNC, credential theft, keylogging, proxying, remote command execution, and persistence via scheduled tasks. The report also states it can survive a factory reset by abusing the Windows recovery partition.
A modular remote access trojan used as the final payload in a multi-stage phishing-driven intrusion. It establishes persistence, enables remote command execution, system reconnaissance, file management, proxying, HVNC, keylogging, credential theft from Chromium-based browsers, and defense evasion including AV/EDR tampering.
A modular, userland-focused remote access trojan/post-exploitation framework designed for persistence, evasion, surveillance, and operator control, with capabilities including keylogging, credential harvesting, RDP, and HVNC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.