BotHelper RAT Uses Encrypted Payloads and Live Screen Surveillance to Spy on Windows Users
Key Takeaways A new Windows Remote Access Trojan (RAT), dubbed BotHelper, has been identified, capable of real-time screen surveillance and device control. The malware employs encrypted payloads,...
Key Takeaways
- A new Windows Remote Access Trojan (RAT), dubbed BotHelper, has been identified, capable of real-time screen surveillance and device control.
- The malware employs encrypted payloads, in-memory execution, and masquerades as legitimate system files to evade detection.
- BotHelper establishes persistence through scheduled tasks and can bypass Windows Antimalware Scan Interface (AMSI).
- Victims face risks including data theft, credential compromise, and further system infection due to the RAT’s extensive capabilities.
Emergence of BotHelper RAT: A Stealthy Surveillance Threat
A sophisticated new remote access trojan (RAT) targeting Windows systems, named BotHelper, has been uncovered, granting adversaries the ability to conduct live screen surveillance and gain comprehensive control over compromised devices. This malware employs a multi-stage infection process, leveraging encryption and masquerading techniques to remain undetected.
Table Of Content
The attack chain initiates with a small, initial program that profiles the victim’s computer, gathering details such as the system name, user, processor specifications, and memory configuration. Subsequently, this starter component establishes an HTTPS connection to a remote command-and-control (C2) server, deliberately bypassing standard certificate validation. It then downloads an encrypted payload directly into memory, where it is decrypted and executed.
Security researchers at Point Wild said in a report that their analysis of this previously undocumented .NET tool revealed a sophisticated approach to Windows intrusion. The initial infection vector, however, remains unconfirmed. Upon successful execution, the decrypted payload is written to the temporary folder, adopting a filename that mimics legitimate Microsoft Edge components, such as Msedge_proxy.exe, to further blend into the system. The RAT then launches invisibly and establishes persistence by creating a hidden copy of itself and a scheduled task to re-execute every 30 minutes, a common tactic seen in other Windows RAT operations.
Encrypted Payloads and Advanced Evasion
The core of BotHelper’s stealth lies in its use of encrypted payloads. The first-stage component retrieves a 52,744-byte opaque data blob from the attacker’s infrastructure. This file lacks typical Windows executable headers and readable strings, effectively thwarting basic reputation analysis tools and static detection methods.
During runtime, a position-dependent XOR routine decrypts this data directly in memory, revealing the executable RAT. Once active, BotHelper communicates with PHP-based server endpoints, using a unique device identifier to check in and receive commands. Researchers observed the C2 server issuing “Screenshot” and “ScreenStreamStart” commands, enabling live surveillance at a rate of three frames per second with JPEG quality set to 40.
The malware captures the entire visible desktop, resizes each frame, encodes it as a JPEG image, and uploads it to the C2 server without saving any images locally on the infected machine. During analysis, frames measuring 1440 by 810 pixels were observed being transmitted at 333-millisecond intervals. The streaming mechanism is robust; failed captures do not interrupt the feed, and a 50-millisecond delay limits the maximum frame rate to 20 frames per second.
This live screen surveillance capability is particularly dangerous, as it can expose sensitive information such as email content, internal application data, confidential documents, security prompts, and real-time account activity, all without the need for direct file exfiltration. This mirrors the broader remote-control capabilities of many RATs, where a single point of compromise can facilitate extensive spying, data theft, and deeper access within a Windows environment.
Persistence and Broader Remote Control
BotHelper’s command handler extends far beyond mere screen capture. It possesses a comprehensive set of remote control functionalities, including the ability to execute arbitrary commands via Command Prompt or PowerShell, download and execute additional files, monitor and manipulate the clipboard, display messages to the user, and even restart or shut down the compromised device. Furthermore, it can load dynamic-link library (DLL) plugins at runtime, indicating an extensible architecture for future capabilities.
The clipboard monitoring feature is particularly concerning, as it could be leveraged for cryptocurrency address substitution, leading to direct financial theft. The combination of encrypted delivery and memory-focused execution makes the infection chain exceedingly difficult to detect and analyze using traditional file-based scanning methods alone.
A notable evasion technique employed by BotHelper is its patching of the Windows Antimalware Scan Interface (AMSI) before initializing its client functions. This behavior is characteristic of encrypted loader evasion methods, where the final malicious payload is concealed until its execution in memory, bypassing many security solutions.
What You Should Do
- Isolate Compromised Hosts: Immediately disconnect any suspected infected systems from the network to prevent further spread and data exfiltration.
- Inspect for Persistence Mechanisms: Examine scheduled tasks for suspicious entries and search for hidden copies of executables in temporary directories (e.g.,
%TEMP%msedge_proxy.exe). - Monitor Network Traffic: Look for unexpected outbound HTTPS connections, especially those bypassing certificate validation, and unusual screen-capture or image-upload activity.
- Implement Endpoint Detection and Response (EDR): Utilize EDR solutions to detect behavioral anomalies across the entire attack chain, including in-memory payload decryption, AMSI tampering, and suspicious child processes.
- Reset Credentials: Reset any potentially exposed user credentials and review active user sessions, as live screen surveillance could have captured sensitive login information.
- Educate Users: Train users to recognize phishing attempts and suspicious downloads, which are common initial vectors for such malware.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.