BotHelper RAT Uses Encrypted Payloads and Live Screen Surveillance to Spy on Windows Users
Point Wild documents BotHelper, a previously unseen .NET Windows RAT delivering encrypted payloads and streaming live victim screen surveillance at up to 20 fps.
Point Wild analysts identified BotHelper RAT, a .NET Windows trojan whose stager profiles the host, downloads a 52,744-byte XOR-encrypted payload over HTTPS from easyllms[.]xyz, and decrypts it in memory under an msedge_proxy.exe disguise in the temp folder. The RAT persists via a scheduled task relaunching every 30 minutes, patches AMSI, and executes server-issued commands including live screen streaming (1440x810 JPEG frames at 3 fps), clipboard monitoring, file download/execution, and DLL plugin loading. Researchers observed Screenshot and ScreenStreamStart commands during live activity, but did not identify the initial delivery vector.