Researchers analyzed Pekraut, a feature-rich .NET remote access trojan believed to be of German origin, and found samples disguised as svchost.exe under %APPDATA%\Microsoft. One sample was packed with ConfuserEx and another obfuscated with Dotfuscator, but both resolved to nearly identical malware after unpacking. The RAT supports 27 commands and uses AES-encrypted text communications, with zlib compression applied to other data types, indicating an operator-ready toolset designed for remote control rather than legitimate administration.
Pekraut establishes persistence by copying itself to %USERPROFILE%\AppData\Roaming\Microsoft\svchost.exe, altering the Winlogon Shell registry value, and creating a startup shortcut named IExplorerUpdate.lnk. It also includes installation and uninstallation routines and a Windows 10 UAC bypass using ComputerDefaults.exe. Investigators said the operator concealed command-and-control infrastructure behind portmap.io, while embedded configuration data exposed a C2 port, authentication ID, and encryption password, suggesting the malware was being prepared for broader distribution through customized builder-generated variants.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Analysis showed the operator used portmap.io to conceal the real command-and-control server IP address. The recovered configuration exposed version 1.1, C2 port 37648, an authentication ID, and an encryption password.
After deobfuscation and manual symbol renaming, researchers documented Pekraut's 27-command feature set, AES-encrypted text communications, zlib compression, persistence mechanisms, uninstallation routine, and a Windows 10 UAC bypass using ComputerDefaults.exe.
A second Pekraut sample was uploaded to VirusTotal one day after the first sample. Unlike the first, it was obfuscated with Dotfuscator rather than packed, and researchers found it was almost identical after unpacking.
One of the Pekraut samples analyzed by researchers had been uploaded to VirusTotal under the name netRat.exe. This sample was packed with ConfuserEx.
Researchers identified a fake svchost.exe in %APPDATA%\Microsoft, which led to the discovery and analysis of the Pekraut .NET remote access trojan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.