BotHelper RAT Live-Streams Windows Victims' Screens While Patching AMSI
Point Wild discloses BotHelper, a previously undocumented .NET Windows RAT whose x64 stager (WindowsUpdate.exe) downloads an XOR-encrypted payload from easyllms[.]xyz, persists via a 30-minute scheduled task, and streams victims' screens as JPEG frames.
Point Wild Threat Intelligence analyzed BotHelper, a previously undocumented .NET Windows implant delivered by a native x64 stager named WindowsUpdate.exe that profiles the host and disables TLS certificate validation before downloading a 52,744-byte XOR-encrypted payload over HTTPS from easyllms[.]xyz. The payload is decrypted in memory and launched from the Temp folder disguised as msedge_proxy.exe. The RAT persists via a scheduled task that relaunches it every 30 minutes and patches AMSI. Its command set covers cmd/PowerShell execution, clipboard monitoring, file download/execution, and plugin DLL loading, alongside live screen streaming of the primary display as JPEG frames. Researchers observed Screenshot and ScreenStreamStart commands during live activity but did not identify the initial delivery vector. The two reports disagree on streaming performance: GBHackers states up to 20 frames per second, while Cyber Security News reports 1440x810 JPEG frames at 3 fps. SHA-256 hashes were published for both the stager and the RAT binary.
- BotHelper is a previously undocumented .NET Windows RAT documented by Point Wild Threat Intelligence.
- Delivered by a native x64 stager named WindowsUpdate.exe that profiles the host and disables TLS certificate validation.
- The stager downloads a 52,744-byte XOR-encrypted payload over HTTPS from easyllms[.]xyz and decrypts it in memory.
- The payload masquerades as msedge_proxy.exe in the Temp folder.
- Persistence is a scheduled task relaunching every 30 minutes, combined with AMSI patching.
- Supported commands include cmd/PowerShell execution, clipboard clipping/monitoring, file download and execution, and loading of plugin DLLs.
- Live screen surveillance streams the primary display as JPEG frames; sources disagree on the rate: up to 20 fps (GBHackers) versus 1440x810 at 3 fps (Cyber Security News).
- Screenshot and ScreenStreamStart commands were observed during live activity.
Coverage timelineoldest first · each row is one article
- · 1d agoResearchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams
GBHackers· 62
Point Wild detailed BotHelper, a Windows RAT that live-streams victim screens and tampers with AMSI.
- · 22h agoBotHelper RAT Uses Encrypted Payloads and Live Screen Surveillance to Spy on Windows Users
Cyber Security News· 48
Point Wild documents BotHelper, a previously unseen .NET Windows RAT delivering encrypted payloads and streaming live victim screen surveillance at up to 20 fps.