Researchers detailed the CSHARP-STREAMER remote access trojan as a modular, memory-resident .NET malware used in ransomware intrusions, including cases tied to Metaencryptor, REvil, LostTrust, and ALPHV/BlackCat. In observed incidents, attackers launched the RAT through a heavily obfuscated PowerShell stager that performed an AMSI bypass, derived an XOR key, retrieved a payload disguised as a PNG, and loaded the .NET assembly directly into memory. The malware then communicated with command-and-control servers over WebSockets on multiple ports, with fallback to ICMP, using RC4-encrypted Protobuf packets.
The RAT supports broad post-compromise activity, including command execution, file discovery and exfiltration, keylogging, credential theft, lateral movement, port scanning, process dumping, payload execution, and Veeam credential extraction. Investigators found it was often paired with external persistence such as scheduled tasks or services rather than maintaining persistence itself, and in one ransomware case it was used to relay traffic across segmented networks. Detection guidance highlighted forensic artifacts including Windows Event ID 2004, a netsh firewall rule opening inbound TCP port 6667, PowerShell Script Block Logging evidence, memory-resident indicators, and the user agent string websocket-sharp/1.0, reinforcing assessments that the malware may be customized or provided as a service across multiple ransomware operations.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
HiSolutions released research and detection guidance for CSHARP-STREAMER, including YARA and Sigma rules, memory-resident indicators, PowerShell Script Block Logging recommendations, firewall-rule monitoring, and the user agent string "websocket-sharp/1.0".
cyber.wtf published a technical analysis of the csharp-streamer RAT, describing its obfuscated PowerShell stager, in-memory .NET loading, WebSocket and ICMP command-and-control, and broad post-exploitation capabilities.
HiSolutions reported a significant increase in observed CSHARP-STREAMER usage in Q3 2023 and linked an August 2023 uptick to Metaencryptor victim postings and LostTrust victim activity.
HiSolutions reported that the AMSI memory bypass used in the PowerShell loader was copied from a script posted on GitHub in August 2022.
The cyber.wtf analysis states that csharp-streamer had existed since at least April 2021 and had previously been identified by Fortgale in a ransomware campaign.
HiSolutions said the XOR decryption component later used in the loader was originally published by security researcher GetRektBoy724 in 2021.
HiSolutions stated that the first in-the-wild samples of CSHARP-STREAMER appeared in the second half of 2020 and likely represented early development versions.
HiSolutions analyzed a ransomware incident involving Metaencryptor in which attackers used a PowerShell loader to decrypt and execute CSHARP-STREAMER in memory and used its relay capability to reach a protected network segment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.