SOC Prime Bias: High

28 Sep 2026 14:51 UTC

BotHelper RAT Delivers Encrypted Payloads for Live Screen Surveillance

Author Photo
SOC Prime Team linkedin icon Follow
BotHelper RAT Delivers Encrypted Payloads for Live Screen Surveillance
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A multi-stage Windows infection chain uses a native stager to retrieve an encrypted payload that ultimately deploys a previously undocumented .NET remote access tool called BotHelper RAT. The RAT supports live screen surveillance, clipboard monitoring, shell command execution, and additional plugin delivery. The attack is designed for stealth through in-memory decryption and masquerading as legitimate Microsoft Edge processes.

Investigation

Point Wild analyzed the infection chain and identified a native x64 stager that profiles the host before downloading an encrypted file from a designated URL. The investigation found that the stager disables TLS certificate validation and decrypts the next-stage payload entirely in memory to reduce disk-based detection. BotHelper RAT then establishes persistence through scheduled tasks and patches the Antimalware Scan Interface (AMSI).

Mitigation

Mitigation should prioritize blocking the initial stager and associated C2 infrastructure. Security controls should detect unauthorized scheduled task creation and suspicious process masquerading, including instances of msedge_proxy.exe running from the Temp directory. Organizations should also monitor for AMSI patching attempts and unusual outbound TLS connections to previously unknown or untrusted domains.

Response

When BotHelper RAT activity is detected, isolate the affected endpoint to stop further command execution and data exfiltration. Remove malicious scheduled tasks and dropped files from the user’s temporary directory. Perform memory forensics to identify additional in-memory components and investigate for evidence of clipboard theft, live screen monitoring, or captured screenshots.

Attack Flow

Detections

Schtasks Points to Suspicious Directory / Binary / Script (via cmdline)

SOC Prime Team
28 Sep 2026

Suspicious Scheduled Task (via audit)

SOC Prime Team
28 Sep 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
28 Sep 2026

IOCs (HashSha256) to detect: BotHelper RAT: From Encrypted Payload to Live Screen Surveillance

SOC Prime AI Rules
28 Sep 2026

IOCs (SourceIP) to detect: BotHelper RAT: From Encrypted Payload to Live Screen Surveillance

SOC Prime AI Rules
28 Sep 2026

IOCs (DestinationIP) to detect: BotHelper RAT: From Encrypted Payload to Live Screen Surveillance

SOC Prime AI Rules
28 Sep 2026

Detect XOR Loop Decryption in BotHelper RAT Payload [Windows Sysmon]

SOC Prime AI Rules
28 Sep 2026

Detected Scheduled Task for BotHelper RAT Persistence [Windows Registry Event]

SOC Prime AI Rules
28 Sep 2026

Detect BotHelper RAT and msedge_proxy.exe Execution [Windows Process Creation]

SOC Prime AI Rules
28 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The attacker has gained initial access and now seeks to maintain a foothold. To evade detection by security tools looking for “always-on” beacons, they decide to use the schtasks.exe utility to schedule a malicious payload. Following the BotHelper RAT pattern, they configure the task to trigger every 30 minutes. This allows the malware to “sleep” most of the time, reducing the footprint in network traffic and process monitoring, while ensuring the connection to the C2 server is re-established frequently.

  • Regression Test Script:

    # Simulation script to mimic BotHelper RAT persistence mechanism
    $taskName = "BotHelperUpdater"
    $payload = "C:WindowsSystem32calc.exe" # Using calc.exe as a safe proxy for the RAT payload
    
    Write-Host "[+] Simulating BotHelper RAT persistence..."
    # This command is designed to match the detection logic: /create, /sc, and MINUTE=30
    schtasks /create /tn "$taskName" /tr "$payload" /sc minute /mo 30 /f
    
    if ($LASTEXITCODE -eq 0) {
        Write-Host "[SUCCESS] Task created. Check SIEM for detection."
    } else {
        Write-Host "[FAILURE] Failed to create task."
    }
  • Cleanup Commands:

    # Remove the simulated persistence task
    schtasks /delete /tn "BotHelperUpdater" /f
    Write-Host "[+] Cleanup complete. Simulated task removed."