BotHelper RAT gives attackers live Windows screen access
Cybersecurity researchers have identified a previously undocumented Windows remote access trojan that can continuously stream an infected computer’s display to its operators while supporting command execution, downloads, clipboard monitoring and other remote-control functions. Point Wild’s Lat61 Threat Intelligence team named the malware BotHelper RAT after the Bot. Helper namespace found in its.…
Researchers have uncovered an undisclosed Windows remote access trojan (RAT) capable of transmitting an infected computer's display to operators while offering a range of remote-control abilities. Named BotHelper RAT, after its .NET assembly namespace, the malware follows a multi-stage infection process starting with a 64-bit Windows stager.
This stager gathers machine details and connects over HTTPS to attacker-controlled servers, downloading an encrypted file. Upon decryption in memory, the malware is disguised as a legitimate Microsoft Edge component and launched without a visible window. BotHelper RAT then establishes persistence by copying itself to a hidden location and creating a scheduled task.
The malware can capture screenshots, monitor the clipboard, execute commands, download additional files, and manage its own client. These features, combined with encrypted delivery, in-memory decryption, and AMSI manipulation, make the RAT a potent threat. Defenders are advised to monitor for suspicious scheduled tasks and unusual connections to untrusted infrastructure.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.