TL;DR

  • CRYSOME (Windows RAT): Built in C# and engineered to maintain a stable TCP-based C2 channel for remote control on infected machines. Uses HVNC, screen streaming, mouse/keyboard injection, credential theft from Chromium, and network pivoting through SOCKS and reverse proxy. Applies strong defense evasion and persistence, including AV killing, scheduled tasks, services, watchdog logic, registry Run keys, and autorun abuse.
  • INFINITY (macOS stealer): Delivered through ClickFix-like social engineering and staged shell/Python execution. Uses Nuitka onefile packaging with zstd compression, anti-sandbox checks, and exfiltrates browser data, Keychain secrets, local files, crypto wallets, and screenshots.
  • BRUSHWORM (Windows backdoor): A modular implant used for persistence, C2 communication, DLL download, USB propagation, and file theft. Stores configuration as AES-CBC-encrypted JSON, uses scheduled tasks for execution, and keeps staged data under Windows-looking directories to blend in.

1) CRYSOME (Windows)

Sample: ANY.RUN

CRYSOME is a RAT built in C#. It is engineered to create and sustain a stable TCP-based command-and-control channel, allowing for a wide range of remote actions on infected machines. The malware combines remote control, surveillance, credential theft, persistence, and defense evasion in a single implant.

How to detect: Detected by monitoring abnormal network activities, files, and mutexes.

Key facts:

  • HVNC for invisible desktop interaction.
  • Reset survival with payload in recovery partition and offline registry hijack.
  • AVKiller behavior: kills security processes, disables Defender, uses IFEO hijacking, blocks AV updates via hosts.
  • Multi-layer persistence through scheduled tasks, services, watchdog logic, hidden copies, and self-relaunch.
  • Full remote control with screen streaming and mouse/keyboard injection.
  • Network pivoting via SOCKS and reverse proxy.
  • Credential theft from Chromium through password and cookie injection.
  • Surveillance capabilities including screen, webcam, microphone, and keylogging.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion VT First Submission
2026-03-31 cyfirma.com 2026-04-01 0 2026-04-01

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: syncObjectName:"crysomeclient."

IOCs:

  • SHA256: d4be83a0a1f2cdbec8df333465d1bbd221f995ed7eebd5670886705c9d34afb8
  • SHA256: f30f32937999abe4fa6e90234773e0528a4b2bd1d6de5323d59ac96cdb58f25d
  • SHA256: cfe781129d8db1dcbfdce5fa3b62157bbd6e7a7e8b7f421a4767189463ef28e0

MITRE:

Technique ID Technique Name Evidence
T1053.005 Scheduled Task/Job: Scheduled Task Modifies existing scheduled task.
T1059.001 Command and Scripting Interpreter: PowerShell Starts POWERSHELL.EXE for command execution.
T1569.002 System Services: Service Execution Starts NET.EXE for service management.
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder Changes the autorun value in the registry.
T1036.005 Masquerading: Match Legitimate Resource Name or Location Creates files with names similar to system file names.
T1222.001 File and Directory Permissions Modification Modifies the hosts file to alter network resolution.
T1562.001 Impair Defenses: Disable or Modify Tools Changes Windows Defender settings.
T1489 Service Stop Uses NET.EXE to stop Windows Security Center service.
T1082 System Information Discovery Reads different system data.
T1012 Query Registry Reads different registry keys.

2) Infiniti (macOS)

Sample: ANY.RUN

Infiniti Stealer is a macOS infostealer distributed through ClickFix-like social engineering and a shell-dropper chain followed by a Python payload packaged with Nuitka. After execution, the malware unfolds a multi-stage chain, extracts the main payload, and collects browser credentials, cookies, Keychain data, local files, and crypto wallets. The gathered information is aggregated and sent to C2. It stands out because of its Python onefile container with zstd packing and its anti-sandbox logic.

How to detect: Detected through characteristic execution artifacts, including creation of a temporary file via mktemp /tmp/.[a-z0-9]{16}XXXXXX and the presence of the debug file /private/tmp/.bs_debug.log.

Key facts:

  • Uses Nuitka onefile for packaging the Python stealer with zstd compression and staged unpacking.
  • Implements a multi-stage chain: shell → loader → main stealer.
  • Steals data from Chromium and Firefox, macOS Keychain, local files, crypto wallets, and extensions.
  • Takes screenshots and gathers additional system information.
  • Applies anti-sandbox checks such as uptime under 180 seconds, fewer than 30 processes, hostname/user/UUID checks, and VM artifact searches.
  • Uses background execution with nohup and removes traces of the dropper.
  • Sends data through a dedicated uploader module to C2.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion VT First Submission
2026-03-27 malwarebytes.com 2026-03-31 0 2026-03-26

IOCs:

  • C2: https[:]//update-check.com/
  • C2 panel: Infiniti-stealer[.]com
  • File path: /private/tmp/.bs_debug.log
  • Process artifact: mktemp /tmp/.[a-z0-9]{16}XXXXXX

MITRE:

Technique ID Technique Name Evidence
T1059.004 Unix Shell Uses a shell script for initial execution.
T1620 Reflective Code Loading Unpacks the Nuitka onefile payload in memory.
T1555 Credentials from Password Stores Collects data from browsers and Keychain.
T1005 Data from Local System Steals local files and secrets.
T1113 Screen Capture Captures screenshots through the screenshot module.
T1497 Virtualization/Sandbox Evasion Checks uptime, process count, and VM artifacts.
T1071.001 Web Protocols Exfiltrates data to C2 over HTTP.

3) BRUSHWORM (Windows)

Sample: ANY.RUN

BRUSHWORM is a modular Windows backdoor observed in a targeted intrusion against a South Asian financial institution. It is the primary implant responsible for installation, persistence, C2 communication, modular DLL download, USB-based propagation, and file theft.

How to detect: Detection based on identifying specific artifacts of malware presence in the operating system: primarily, the presence of an encrypted configuration file whose path matches ^C:\\Users\\Public\\AppData\\Roaming\\Microsoft\\Vault\\keyE\.dat$, together with the companion artifacts C:\ProgramData\YourApp\machine_seed.dpapi and C:\Users\Public\AppData\Roaming\Microsoft\Vault\key.dat, as well as the BRUSHWORM C2/download endpoint resources.dawnnewsisl.com/updtdll.

Key facts:

  • BRUSHWORM is the primary implant in a custom malware set that also included a DLL-side-loaded keylogger; the backdoor supports persistence, modular payload download, removable-media propagation, and file theft.
  • The configuration is stored as AES-CBC-encrypted JSON with the fields internetCheckDomain, downloadDomain, and retryCount; these fields are unused in the analyzed build, while the real C2 string is a cleartext global value pointing to resources.dawnnewsisl.com/updtdll.
  • The backdoor creates a scheduled task named MSGraphics for persistence, then uses a GET request to /updtdll to download Recorder.dll, which is later launched through a second scheduled task named MSRecorder using rundll32.exe.
  • BRUSHWORM has basic anti-analysis checks: screen resolution below 1024×768, username/computer-name checks for sandbox, CPUID hypervisor vendor-string checks, and a mouse-activity check that requires movement within five minutes.
  • BRUSHWORM checks connectivity by attempting to reach www.google.com, then copies itself to removable drives and stages stolen files under C:\Users\Public\Systeminfo\, with a tracking file under C:\Users\Public\AppData\Roaming\NuGet\ to avoid re-exfiltration.
  • Hardcoded directories such as C:\ProgramData\Photoes\Pics\, C:\Users\Public\Libraries\, C:\Users\Public\AppData\Roaming\Microsoft\Vault\, C:\Users\Public\Systeminfo\, and C:\Users\Public\AppData\Roaming\NuGet\ are part of the malware’s file layout.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2026-03-28 elastic.co 2026-03-31 2

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"C:\\Users\\Public\\AppData\\Roaming\\Microsoft\\Vault\\key.dat"

IOCs:

  • SHA256: 89891aa3867c1a57512d77e8e248d4a35dd32e99dcda0344a633be402df4a9a7
  • URL: resources.dawnnewsisl[.]com
  • IP: 151.243.137[.]244

MITRE:

Technique ID Technique Name Evidence
T1053.005 Scheduled Task/Job: Scheduled Task Creates scheduled tasks MSGraphics and MSRecorder for persistence and execution.
T1071.001 Application Layer Protocol: Web Protocols Uses web requests to the C2/download endpoint /updtdll.
T1105 Ingress Tool Transfer Downloads Recorder.dll from the C2 server.
T1027 Obfuscated Files or Information Configuration fields are AES-CBC-encrypted before storage in keyE.dat.
T1497.001 Virtualization/Sandbox Evasion: System Checks Screen resolution, sandbox-name, CPUID hypervisor, and mouse-activity checks are used to evade analysis.
T1074.001 Data Staged: Local Data Staging Stolen files are staged in C:\Users\Public\Systeminfo\, with hash tracking in ...\NuGet\hashconfig.
T1036 Masquerading Hardcoded locations and names such as Photoes, MSGraphics, and Recorder.dll are designed to blend with legitimate Windows-looking paths and file names.

Conclusion

  • CRYSOME leaves a strong combination of network, mutex, and persistence artifacts, with crysomeclient. being a useful hunting marker for the implant.

  • Infiniti is easiest to spot through its macOS execution artifacts, especially /private/tmp/.bs_debug.log and the mktemp /tmp/.[a-z0-9]{16}XXXXXX pattern.

  • BRUSHWORM can be reliably identified by the encrypted vault configuration path C:\Users\Public\AppData\Roaming\Microsoft\Vault\keyE.dat together with its staged Windows-like directories and C2 download path.

  • Across all three families, the most reliable detection strategy is to combine behavioral telemetry with the file, mutex, and network artifacts listed above.