BotHelper RAT Delivers Encrypted Payloads for Live Screen Surveillance
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A multi-stage Windows infection chain uses a native stager to retrieve an encrypted payload that ultimately deploys a previously undocumented .NET remote access tool called BotHelper RAT. The RAT supports live screen surveillance, clipboard monitoring, shell command execution, and additional plugin delivery. The attack is designed for stealth through in-memory decryption and masquerading as legitimate Microsoft Edge processes.
Investigation
Point Wild analyzed the infection chain and identified a native x64 stager that profiles the host before downloading an encrypted file from a designated URL. The investigation found that the stager disables TLS certificate validation and decrypts the next-stage payload entirely in memory to reduce disk-based detection. BotHelper RAT then establishes persistence through scheduled tasks and patches the Antimalware Scan Interface (AMSI).
Mitigation
Mitigation should prioritize blocking the initial stager and associated C2 infrastructure. Security controls should detect unauthorized scheduled task creation and suspicious process masquerading, including instances of msedge_proxy.exe running from the Temp directory. Organizations should also monitor for AMSI patching attempts and unusual outbound TLS connections to previously unknown or untrusted domains.
Response
When BotHelper RAT activity is detected, isolate the affected endpoint to stop further command execution and data exfiltration. Remove malicious scheduled tasks and dropped files from the user’s temporary directory. Perform memory forensics to identify additional in-memory components and investigate for evidence of clipboard theft, live screen monitoring, or captured screenshots.
Attack Flow
Detections
Schtasks Points to Suspicious Directory / Binary / Script (via cmdline)
Suspicious Scheduled Task (via audit)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: BotHelper RAT: From Encrypted Payload to Live Screen Surveillance
IOCs (SourceIP) to detect: BotHelper RAT: From Encrypted Payload to Live Screen Surveillance
IOCs (DestinationIP) to detect: BotHelper RAT: From Encrypted Payload to Live Screen Surveillance
Detect XOR Loop Decryption in BotHelper RAT Payload [Windows Sysmon]
Detected Scheduled Task for BotHelper RAT Persistence [Windows Registry Event]
Detect BotHelper RAT and msedge_proxy.exe Execution [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The attacker has gained initial access and now seeks to maintain a foothold. To evade detection by security tools looking for “always-on” beacons, they decide to use the
schtasks.exeutility to schedule a malicious payload. Following the BotHelper RAT pattern, they configure the task to trigger every 30 minutes. This allows the malware to “sleep” most of the time, reducing the footprint in network traffic and process monitoring, while ensuring the connection to the C2 server is re-established frequently. -
Regression Test Script:
# Simulation script to mimic BotHelper RAT persistence mechanism $taskName = "BotHelperUpdater" $payload = "C:WindowsSystem32calc.exe" # Using calc.exe as a safe proxy for the RAT payload Write-Host "[+] Simulating BotHelper RAT persistence..." # This command is designed to match the detection logic: /create, /sc, and MINUTE=30 schtasks /create /tn "$taskName" /tr "$payload" /sc minute /mo 30 /f if ($LASTEXITCODE -eq 0) { Write-Host "[SUCCESS] Task created. Check SIEM for detection." } else { Write-Host "[FAILURE] Failed to create task." } -
Cleanup Commands:
# Remove the simulated persistence task schtasks /delete /tn "BotHelperUpdater" /f Write-Host "[+] Cleanup complete. Simulated task removed."