216.73.217.22

CrySome RAT : An Advanced Persistent .NET Remote Access Trojan

· Published 31/03/2026 16:14 · Modified 31/03/2026 18:49

Export JSON

Essential information

Published
31/03/2026 16:14
Modified
31/03/2026 18:49
Tags
.net 2026-03-31 avkiller c++ credential-theft crysome rat defense evasion hvnc persistence rat remote access stealth
Related entities
2 observables, 24 techniques (mitre), 1 malware, 1 others

Description

CrySome is a sophisticated .NET-based trojan designed for persistent command-and-control operations. It features advanced mechanisms, including recovery partition abuse and offline registry modification, allowing it to survive system resets. The malware incorporates an aggressive module, disabling security products and blocking updates. Key capabilities include command execution, file operations, surveillance, credential theft, and hidden virtual desktop control. CrySome's modular architecture and structured packet-based protocol enable a wide range of remote operations. Its emphasis on , resilience, and comprehensive system control makes it a significant threat for long-term covert access to compromised environments.

External references