Researchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams
Point Wild detailed BotHelper, a Windows RAT that live-streams victim screens and tampers with AMSI.
Point Wild Threat Intelligence analyzed BotHelper RAT, a previously undocumented .NET Windows implant delivered by a native x64 stager. The stager disables TLS certificate validation, downloads an XOR-encrypted payload from easyllms.xyz, and launches it from Temp as msedge_proxy.exe. The RAT schedules relaunch every 30 minutes, patches AMSI, and can stream the screen, run shell and PowerShell, monitor the clipboard, and load plugin DLLs. Researchers published SHA-256 hashes for the stager WindowsUpdate.exe and the RAT binary.
62