TL;DR

Sample: ANY.RUN
CRYSOME is a RAT built in C#. It is engineered to create and sustain a stable TCP-based command-and-control channel, allowing for a wide range of remote actions on infected machines. The malware combines remote control, surveillance, credential theft, persistence, and defense evasion in a single implant.
How to detect: Detected by monitoring abnormal network activities, files, and mutexes.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion | VT First Submission |
|---|---|---|---|---|
| 2026-03-31 | cyfirma.com | 2026-04-01 | 0 | 2026-04-01 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
syncObjectName:"crysomeclient."
IOCs:
d4be83a0a1f2cdbec8df333465d1bbd221f995ed7eebd5670886705c9d34afb8f30f32937999abe4fa6e90234773e0528a4b2bd1d6de5323d59ac96cdb58f25dcfe781129d8db1dcbfdce5fa3b62157bbd6e7a7e8b7f421a4767189463ef28e0MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1053.005 | Scheduled Task/Job: Scheduled Task | Modifies existing scheduled task. |
| T1059.001 | Command and Scripting Interpreter: PowerShell | Starts POWERSHELL.EXE for command execution. |
| T1569.002 | System Services: Service Execution | Starts NET.EXE for service management. |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Changes the autorun value in the registry. |
| T1036.005 | Masquerading: Match Legitimate Resource Name or Location | Creates files with names similar to system file names. |
| T1222.001 | File and Directory Permissions Modification | Modifies the hosts file to alter network resolution. |
| T1562.001 | Impair Defenses: Disable or Modify Tools | Changes Windows Defender settings. |
| T1489 | Service Stop | Uses NET.EXE to stop Windows Security Center service. |
| T1082 | System Information Discovery | Reads different system data. |
| T1012 | Query Registry | Reads different registry keys. |

Sample: ANY.RUN
Infiniti Stealer is a macOS infostealer distributed through ClickFix-like social engineering and a shell-dropper chain followed by a Python payload packaged with Nuitka. After execution, the malware unfolds a multi-stage chain, extracts the main payload, and collects browser credentials, cookies, Keychain data, local files, and crypto wallets. The gathered information is aggregated and sent to C2. It stands out because of its Python onefile container with zstd packing and its anti-sandbox logic.
How to detect: Detected through characteristic execution artifacts, including creation of a temporary file via mktemp /tmp/.[a-z0-9]{16}XXXXXX and the presence of the debug file /private/tmp/.bs_debug.log.
Key facts:
nohup and removes traces of the dropper.Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion | VT First Submission |
|---|---|---|---|---|
| 2026-03-27 | malwarebytes.com | 2026-03-31 | 0 | 2026-03-26 |
IOCs:
https[:]//update-check.com/Infiniti-stealer[.]com/private/tmp/.bs_debug.logmktemp /tmp/.[a-z0-9]{16}XXXXXXMITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059.004 | Unix Shell | Uses a shell script for initial execution. |
| T1620 | Reflective Code Loading | Unpacks the Nuitka onefile payload in memory. |
| T1555 | Credentials from Password Stores | Collects data from browsers and Keychain. |
| T1005 | Data from Local System | Steals local files and secrets. |
| T1113 | Screen Capture | Captures screenshots through the screenshot module. |
| T1497 | Virtualization/Sandbox Evasion | Checks uptime, process count, and VM artifacts. |
| T1071.001 | Web Protocols | Exfiltrates data to C2 over HTTP. |

Sample: ANY.RUN
BRUSHWORM is a modular Windows backdoor observed in a targeted intrusion against a South Asian financial institution. It is the primary implant responsible for installation, persistence, C2 communication, modular DLL download, USB-based propagation, and file theft.
How to detect: Detection based on identifying specific artifacts of malware presence in the operating system: primarily, the presence of an encrypted configuration file whose path matches ^C:\\Users\\Public\\AppData\\Roaming\\Microsoft\\Vault\\keyE\.dat$, together with the companion artifacts C:\ProgramData\YourApp\machine_seed.dpapi and C:\Users\Public\AppData\Roaming\Microsoft\Vault\key.dat, as well as the BRUSHWORM C2/download endpoint resources.dawnnewsisl.com/updtdll.
Key facts:
internetCheckDomain, downloadDomain, and retryCount; these fields are unused in the analyzed build, while the real C2 string is a cleartext global value pointing to resources.dawnnewsisl.com/updtdll.MSGraphics for persistence, then uses a GET request to /updtdll to download Recorder.dll, which is later launched through a second scheduled task named MSRecorder using rundll32.exe.www.google.com, then copies itself to removable drives and stages stolen files under C:\Users\Public\Systeminfo\, with a tracking file under C:\Users\Public\AppData\Roaming\NuGet\ to avoid re-exfiltration.C:\ProgramData\Photoes\Pics\, C:\Users\Public\Libraries\, C:\Users\Public\AppData\Roaming\Microsoft\Vault\, C:\Users\Public\Systeminfo\, and C:\Users\Public\AppData\Roaming\NuGet\ are part of the malware’s file layout.Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-03-28 | elastic.co | 2026-03-31 | 2 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"C:\\Users\\Public\\AppData\\Roaming\\Microsoft\\Vault\\key.dat"
IOCs:
89891aa3867c1a57512d77e8e248d4a35dd32e99dcda0344a633be402df4a9a7resources.dawnnewsisl[.]com151.243.137[.]244MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1053.005 | Scheduled Task/Job: Scheduled Task | Creates scheduled tasks MSGraphics and MSRecorder for persistence and execution. |
| T1071.001 | Application Layer Protocol: Web Protocols | Uses web requests to the C2/download endpoint /updtdll. |
| T1105 | Ingress Tool Transfer | Downloads Recorder.dll from the C2 server. |
| T1027 | Obfuscated Files or Information | Configuration fields are AES-CBC-encrypted before storage in keyE.dat. |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | Screen resolution, sandbox-name, CPUID hypervisor, and mouse-activity checks are used to evade analysis. |
| T1074.001 | Data Staged: Local Data Staging | Stolen files are staged in C:\Users\Public\Systeminfo\, with hash tracking in ...\NuGet\hashconfig. |
| T1036 | Masquerading | Hardcoded locations and names such as Photoes, MSGraphics, and Recorder.dll are designed to blend with legitimate Windows-looking paths and file names. |
CRYSOME leaves a strong combination of network, mutex, and persistence artifacts, with crysomeclient. being a useful hunting marker for the implant.
Infiniti is easiest to spot through its macOS execution artifacts, especially /private/tmp/.bs_debug.log and the mktemp /tmp/.[a-z0-9]{16}XXXXXX pattern.
BRUSHWORM can be reliably identified by the encrypted vault configuration path C:\Users\Public\AppData\Roaming\Microsoft\Vault\keyE.dat together with its staged Windows-like directories and C2 download path.
Across all three families, the most reliable detection strategy is to combine behavioral telemetry with the file, mutex, and network artifacts listed above.