SummaryA multi-stage Windows infection chain uses a native stager to retrieve an encrypted payload that ultimately deploys a previously undocumented .NET remote access tool called BotHelper RAT.
The RAT supports live screen surveillance, clipboard monitoring, shell command execution, and additional plugin delivery.
BotHelper RAT then establishes persistence through scheduled tasks and patches the Antimalware Scan Interface (AMSI).
ResponseWhen BotHelper RAT activity is detected, isolate the affected endpoint to stop further command execution and data exfiltration.
Remove malicious scheduled tasks and dropped files from the user’s temporary directory.
Summary
A multi-stage Windows infection chain uses a native stager to retrieve an encrypted payload that ultimately deploys a previously undocumented .NET remote access tool called BotHelper RAT. The RAT supports live screen surveillance, clipboard monitoring, shell command execution, and additional plugin delivery. The attack is designed for stealth through in-memory decryption and masquerading as legitimate Microsoft Edge processes.
Investigation
Point Wild analyzed the infection chain and identified a native x64 stager that profiles the host before downloading an encrypted file from a designated URL. The investigation found that the stager disables TLS certificate validation and decrypts the next-stage payload entirely in memory to reduce disk-based detection. BotHelper RAT then establishes persistence through scheduled tasks and patches the Antimalware Scan Interface (AMSI).
Mitigation
Mitigation should prioritize blocking the initial stager and associated C2 infrastructure. Security controls should detect unauthorized scheduled task creation and suspicious process masquerading, including instances of msedge_proxy.exe running from the Temp directory. Organizations should also monitor for AMSI patching attempts and unusual outbound TLS connections to previously unknown or untrusted domains.
Response
When BotHelper RAT activity is detected, isolate the affected endpoint to stop further command execution and data exfiltration. Remove malicious scheduled tasks and dropped files from the user’s temporary directory. Perform memory forensics to identify additional in-memory components and investigate for evidence of clipboard theft, live screen monitoring, or captured screenshots.