Point Wild’s Lat61 Threat Intelligence Team has documented a previously unknown .NET remote access tool. The team calls it BotHelper RAT, after the Bot.Helper namespace in its code.
It arrives through an encrypted download and a file disguised as a Microsoft Edge component. It then watches victims’ screens live.
The attack starts with a small native x64 stager. It profiles the host by collecting the computer name, logged-in user, processor details, and installed memory.
BotHelper RAT Disguised as Microsoft Edge File
It then connects over HTTPS to easyllms[.]xyz and requests payload.bin from a path guarded by a long hexadecimal string. The stager disables TLS certificate validation first, so the download succeeds whatever certificate the server presents.
Researchers say the 52,744-byte file has no MZ header, readable strings, or recognizable structure. The server labels it application/octet-stream. A URL scan showed no detections across 90 engines, even though the address serves a working RAT.

The stager rebuilds the file in memory in 8 KB blocks. It then decrypts it with a position-dependent XOR loop that needs no stored key. The result is a Windows executable.
The stager writes it to %TEMP% as msedge_proxy.exe and launches it with no visible window. A bot_log.txt file appears beside it, recording stages such as “vm ok,” “amsi ok,” and “setup ok.”
BotHelper runs setup, a mutex check, an AMSI patch, and client preparation, in that order. It copies itself to a hidden location and registers a scheduled task through schtasks to relaunch every 30 minutes. Deleting the temp copy therefore doesn’t remove the infection.
The client posts its device ID to ping.php. If the server answers hwidnotfound, the client registers through connect.php. The registration line carries its group, device ID, user and machine name, Windows version, privilege level, and version.
In the observed session, the reply carried commands for a screenshot and ScreenStreamStart at 3 frames per second and quality 40.
The client captures the full desktop, shrinks it and encodes it as JPEG. It uploads the frames to screen_live.php, and writes nothing to disk. A 50 ms floor caps the stream at 20 fps. During analysis, frames measured 1440 × 810 and weighed about 81–82 KB.
The CommandCenter() dispatcher shows how much the operator can do:
- Run commands through cmd or PowerShell.
- Download and run files from a URL or from /uploads/Files/.
- Start or stop clipboard monitoring. ClipperStart usually means cryptocurrency address substitution, which points to financial theft.
- Reboot, shut down, or log off the host.
- Update, restart, or remove the client.
- Load .dll plugins from /uploads/Plugins/ at runtime.
The plugin option means the known feature list is a minimum. Operators can add capabilities without replacing the deployed binary.
Network captures show the infected host reaching 172.67.187.30 over TLS 1.3, with easyllms[.]xyz in the Server Name Indication field.
Because URL and file reputation checks miss the encrypted blob, Point Wild says detection must rely on endpoint behavior after download. The company recommends its UltraAV product to catch the first-stage file.
Defenders should look for these signs:
- Unexpected msedge_proxy.exe files in %TEMP%.
- Scheduled tasks that run every 30 minutes.
- Outbound connections to easyllms[.]xyz.
- AMSI tampering.
Removing the dropped executable alone won’t clean an infected machine. The scheduled task must go too.
Point Wild recovered the payload while the server was still live. Once the server goes offline, the stager yields nothing, and the second stage can’t be recovered from the sample. That limits later analysis of this delivery pattern.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.