FILEMembers
FILE

Packed .NET Stealer Hits Healthcare in 7 Countries With Sandbox-Aware Evasion

A 593 KB unsigned .NET assembly has targeted healthcare organisations across Belgium, India, Italy, Sri Lanka, Pakistan, Tunisia, and the United States since March 2026. The malware layers a forged future timestamp, a runtime-resolving packer, and sandbox-timing delays to frustrate analysis, while beaconing over a TLS channel bearing a decade-old self-signed certificate linked to both AsyncRAT and DCRat infrastructure.

May 29, 2026, 02:45 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamIOC5MITRE24RegionsBEINITLKPK

A 593-kilobyte .NET assembly, unsigned and unremarkable in appearance, has been circulating against healthcare organisations across Belgium, India, Italy, Sri Lanka, Pakistan, Tunisia, and the United States since at least March 2026. What makes it analytically interesting is not its payload — credential theft is commodity work — but the layered effort its operators invested in making sure analysts never get a clean look at it.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence