New CrySome RAT Malware Features AV Killer and HVNC Modules

CrySome RAT is a newly observed, advanced .NET remote access trojan that gives attackers complete remote control over compromised Windows machines.

First identified in March 2026, this malware is written in C#. It employs a modular architecture to execute commands, gather system information, and deploy evasion techniques. Unlike standard remote access tools, CrySome is packaged using Costura.

Fody, which embeds all dependent assemblies into a single executable. This approach simplifies the delivery process for threat actors while inflating the file size with managed resources.

Upon execution, the malware establishes a continuous TCP connection to its command-and-control server. It transmits detailed host profiles, including active window titles, to help operators understand user activity in real time.

Features and Defense Evasion

The technical capabilities of the CrySome RAT extend far beyond simple command execution, turning it into a comprehensive surveillance and system-control platform.

The payload conditionally enables features through a structured, packet-based protocol that functions as a remote application programming interface (API).

CrySome RAT Adds HVNC (Source: cyfirma)
CrySome RAT Adds HVNC (Source: cyfirma)

Operators can remotely execute shell and PowerShell commands, manipulate files, and hijack active system processes.

Furthermore, the malware boasts extensive surveillance capabilities, allowing attackers to secretly capture screenshots, record audio from microphones, capture webcam images, and globally log keystrokes to steal sensitive credentials.

CrySome RAT Adds HVNC (Source: cyfirma)
CrySome RAT Adds HVNC (Source: cyfirma)

Persistence and Threat Landscape

The persistence engineering behind CrySome RAT demonstrates a deliberate design to outlive traditional remediation techniques, including system resets and basic cleanup efforts.

The malware employs a multi-layered survival strategy that includes creating scheduled tasks, modifying the RunOnce registry key, and installing an auto-restarting Windows service.

To protect itself from removal, CrySome locks its own executable file, hides its path, and creates redundant backup copies in legitimate-looking directories.

It also launches a secondary watchdog process to monitor the main executable, ensuring automatic recovery if the primary process is terminated.

CrySome RAT Adds HVNC (Source: cyfirma)
CrySome RAT Adds HVNC (Source: cyfirma)

The most advanced persistence mechanism deployed by CrySome involves manipulating the Windows recovery partition.

The malware copies its executable to the recovery directory. It modifies the offline registry to ensure execution during the next system initialization.

Because the payload resides in the recovery environment and modifies offline configurations, it can survive a full factory reset, making the infection exceptionally difficult to eradicate.

AttributeValueContext
Malware NameCrySome RATFeature-rich C# .NET remote access trojan .
Client ExecutableCrysome.Client.exeUsed for initial infection and execution on victim machines.

Currently, the threat actors behind CrySome RAT distribute the cyfirma malware through a publicly accessible surface web portal.

The platform offers multiple subscription tiers at low prices, complete with ongoing support, updates, and optional built-in encryption features.

While the project remains under active development as of March 2026, cracked versions have already begun circulating on underground forums and Telegram channels, significantly increasing the risk of widespread deployment.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories