Researchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams
Point Wild detailed BotHelper, a Windows RAT that live-streams victim screens and tampers with AMSI.
Point Wild Threat Intelligence analyzed BotHelper RAT, a previously undocumented .NET Windows implant delivered by a native x64 stager. The stager disables TLS certificate validation, downloads an XOR-encrypted payload from easyllms.xyz, and launches it from Temp as msedge_proxy.exe. The RAT schedules relaunch every 30 minutes, patches AMSI, and can stream the screen, run shell and PowerShell, monitor the clipboard, and load plugin DLLs. Researchers published SHA-256 hashes for the stager WindowsUpdate.exe and the RAT binary.
- BotHelper streams the primary display as JPEG at up to 20 frames per second.
- An x64 stager downloads an XOR-encrypted payload from easyllms.xyz over HTTPS.
- Persistence is a scheduled task every 30 minutes plus AMSI patching.
- Commands cover shell, PowerShell, clipboard clipper, file execution, and plugin DLLs.
- IOCs include msedge_proxy.exe in Temp and two published SHA-256 hashes.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | easyllms.xyz | essor configuration and installed memory, before contacting easyllms[.]xyz over HTTPS. It then requests an encrypted second-stage fi |
| sha256 | 0d41ce75da4f3404734358411a72ffc4169376dcfebda52ac50eb66eac73d2f6 | 3a868ff846ade86124a57041f5c63fd Msedge_proxy.exe (RAT file) 0d41ce75da4f3404734358411a72ffc4169376dcfebda52ac50eb66eac73d2f6 C2 easyllms[.]xyz Note: IP addresses and domains are intent |
| sha256 | 8f39fe882e45dfa8a7446d59dfef86b583a868ff846ade86124a57041f5c63fd | compromise Filename SHA-256 WindowsUpdate.exe (Stager file) 8f39fe882e45dfa8a7446d59dfef86b583a868ff846ade86124a57041f5c63fd Msedge_proxy.exe (RAT file) 0d41ce75da4f3404734358411a72ffc |
Full article873 words · extracted from gbhackers.com · click to collapse
A previously undocumented Windows remote access trojan capable of turning an infected victim’s display into a live stream for its operators.
Dubbed BotHelper RAT after the Bot.Helper namespace found in its .NET assembly, the malware uses encrypted delivery, process masquerading, AMSI tampering and scheduled-task persistence to remain operational while giving attackers continuous visual access to compromised systems.
Point Wild Threat Intelligence traced the activity to a multi-stage infection chain beginning with a small native x64 stager.
The first-stage component collects basic host information, including the computer name, logged-on username, processor configuration and installed memory, before contacting easyllms[.]xyz over HTTPS.
It then requests an encrypted second-stage file, payload.bin, from a long hexadecimal URL path.
The initial downloader disables TLS certificate validation before retrieving the payload. This enables the malware to accept invalid or self-signed certificates, reducing the effectiveness of certificate-based network controls.
The file is downloaded in 8 KB chunks and reassembled in memory, limiting the amount of immediately useful content exposed to static scanners and network inspection systems.
The 52,744-byte payload arrives as an opaque binary blob without a recognizable PE header, readable strings or obvious structure.
Instead of embedding a static decryption key, the stager uses a position-dependent XOR routine that regenerates the required keying material during execution.
Once decrypted in memory, the payload reveals a Windows Portable Executable, which is written to the victim’s Temp folder as msedge_proxy.exe.
The filename is intended to resemble a legitimate Microsoft Edge related component before the stager launches it with a hidden window.
The second-stage executable is BotHelper RAT, a .NET implant with surveillance, execution and post-compromise capabilities.

On startup, it copies itself to a hidden location, creates a scheduled task designed to relaunch it every 30 minutes, and patches the Antimalware Scan Interface.
That combination gives the malware both persistence and a potential means of weakening script and content inspection on the affected host.
Windows RAT Espionage
Point Wild Researchers said that, BotHelper checks in with PHP-based command-and-control endpoints hosted under the same infrastructure used to serve the encrypted payload.
The log records BotHelper’s progress in plain text start, vm ok, setup ok, amsi ok, gen ok, one line per completed stage.
The client initially sends a device identifier to ping.php; if the server does not recognize it, the malware registers through connect.php with host and operating-system details, privilege information and a user-and-machine identifier.

Researchers found that the server’s response can also include tasking instructions, effectively merging victim registration and command delivery into one channel.
The most notable observed command sequence began with a screenshot request and continued with ScreenStreamStart, configured at three frames per second and JPEG quality 40.
BotHelper captures the primary display, resizes the image, encodes it as JPEG and uploads each frame to screen_live.php using a filename derived from the victim’s device ID.

UltraAV, powered by Point Wild, focuses on exactly that catching the initial-stage file before the chain can continue.
The implementation retains frames in memory rather than writing them to disk, limiting forensic artifacts associated with surveillance activity.
The malware also enforces a 50-millisecond delay floor, capping screen-capture activity at 20 frames per second even if an operator requests a higher rate.
Screen streaming is only one component of BotHelper’s functionality. Its command dispatcher supports screenshot capture, shell and PowerShell execution, file download-and-execution, clipboard monitoring, host reboot, shutdown and logoff operations, client updates, self-removal and plugin loading.
The plugin feature allows operators to download DLLs dynamically, meaning the built-in command set likely represents a minimum capability baseline rather than the full range of possible actions.
The ClipperStart command is particularly concerning because clipboard “clipper” functionality is commonly associated with cryptocurrency theft, where malware monitors and replaces copied wallet addresses.
Combined with visual surveillance and arbitrary command execution, BotHelper could support credential theft, financial fraud, reconnaissance and follow-on payload delivery.
Defenders should investigate unexpected instances of msedge_proxy.exe executing from %TEMP%, especially when paired with new scheduled tasks, hidden executable copies, AMSI modification attempts or outbound TLS sessions to easyllms[.]xyz.
Point Wild observed TLS 1.3 traffic where the ClientHello Server Name Indication exposed the domain name, providing a potential network-hunting signal despite encrypted application traffic.
Organizations detecting the activity should isolate affected devices, remove malicious scheduled tasks and persistence copies, inspect memory for decrypted payloads, and review the endpoint for command execution, clipboard theft and screen-capture evidence.
The campaign demonstrates how encrypted payload delivery and in-memory decryption can leave traditional reputation-based controls with little to inspect until the attack has already reached the endpoint.
Indicators of compromise
| Filename | SHA-256 |
| WindowsUpdate.exe (Stager file) | 8f39fe882e45dfa8a7446d59dfef86b583a868ff846ade86124a57041f5c63fd |
| Msedge_proxy.exe (RAT file) | 0d41ce75da4f3404734358411a72ffc4169376dcfebda52ac50eb66eac73d2f6 |
| C2 | easyllms[.]xyz |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.