A multi-stage Windows malware chain has been documented in which a Python-based loader uses ctypes and .NET reflection to execute in memory, then patches AmsiScanBuffer and EtwEventWrite to weaken Microsoft antimalware scanning and event tracing before loading a base64-encoded .NET payload. The technique mirrors publicly discussed live DLL patching methods and shows how Python can be used to modify security-relevant functions at runtime to evade detection.
The decoded second stage is a PE32+ Mono/.NET assembly that copies itself to %LOCALAPPDATA%\Microsoft\_OneDrive.exe, creates %LOCALAPPDATA%\Xbox, and establishes persistence through an HKCU registry key and a Startup-folder shortcut that launches PowerShell. It then decodes and launches another embedded payload via aspnet_compiler.exe, ultimately deploying SwaetRAT, which copies itself to %APPDATA%\CCleaner.exe; the recovered configuration points to a command-and-control server at 144[.]126[.]149[.]221:7777, and the malware family matches samples previously observed in earlier campaigns.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The SANS analysis states that eSentire had previously covered the same SwaetRAT sample in 2023, indicating the malware had been documented before the 2025 write-up.
SANS Internet Storm Center published an analysis of a multi-stage Windows malware chain in which a Python loader patched AMSI and ETW functions in memory, launched a .NET stage, and ultimately deployed SwaetRAT. The analysis identified persistence mechanisms, file paths, and the final command-and-control endpoint 144[.]126[.]149[.]221:7777.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
dshield.org
Open sourceisc.sans.edu
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.