PULSE NAME
CrySome RAT : An Advanced Persistent .NET Remote Access Trojan
WHITE AlienVault 2026-03-31 Modified: 2026-03-31
8
IOCs
LOW VOLUME
CrySome is a sophisticated .NET-based remote access trojan designed for persistent command-and-control operations. It features advanced persistence mechanisms, including recovery partition abuse and offline registry modification, allowing it to survive system resets. The malware incorporates an aggressive defense evasion module, disabling security products and blocking updates. Key capabilities include command execution, file operations, surveillance, credential theft, and hidden virtual desktop control. CrySome's modular architecture and structured packet-based protocol enable a wide range of remote operations. Its emphasis on stealth, resilience, and comprehensive system control makes it a significant threat for long-term covert access to compromised environments.
Indicators of Compromise (8)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 03898be29fb6c5464b28ae0239713b7b 2026-03-31
FileHash-MD5 d5e2eb1366ac6a691b5aaad8bec11727 2026-03-31
FileHash-SHA1 a89158fe7d762dca8f136498a4120e3597933cab 2026-03-31
FileHash-SHA1 b4070db8f451731ab768a530f6738cc1800a300b 2026-03-31
FileHash-SHA256 f30f32937999abe4fa6e90234773e0528a4b2bd1d6de5323d59ac96cdb58f25d 2026-03-31
FileHash-SHA256 fa896cc8ce13c69f6306eff2a8698998b48b422784053df6bb078c17fe3f04c3 2026-03-31
FileHash-SHA1 61d065d0afd03bac6a42cb39d48115f66b9fb3ff 2026-03-31
domain crysome.net 2026-03-31