typeentityconfidencehighcreated2026-08-07updated2026-08-07loaderdotnetanti-analysisevasionmalware-familysocial-engineering-filename-lureversion-info-masquerade

moonshine-aot-loader

Malware family built on a custom .NET Native AOT runtime framework named Moonshine.Core. Distributed under purchase-order and banking-document social-engineering lures. The threat logic lives in a high-entropy .gfx PE section that is decrypted at runtime, leaving the .text section as a minimal AOT bootstrap stub.

Observed Samples

SHA-256 Prefix Size Timestamp Filename Notes
02da37c3... 1.05 MB 2026-05-26 PO-20260527.exe Purchase-order lure, .gfx payload, "Aether Sync Agent" masquerade. ^[raw/analyses/02da37c3.../report.md]
21bf44a6... 3.89 MB — yea8hw1uN1NGD0za.exe OpenCTI co-labels: rat, remcos, remcosrat, zigcryptostealer. Likely mislabelled.
29eb0a9e... 1.25 MB — raw hash filename OpenCTI labels: exe, malware-bazaar. Minimal metadata.
35294411... 1.25 MB — qwe-23wq-e.exe OpenCTI co-labels: dropped-by-acrstealer, dropped-by-remusstealer, zigclipper. Likely mislabelled.
433ff5fd... 11.9 MB — file OpenCTI co-labels: d52f85, dropped-by-amadey. Large variant, possibly bundled payload.
52bd61ba... 1.56 MB — Bonifico n.1101252230290346.docx.exe Italian banking lure (unicredit, spam-ita).
7550b526... 1.56 MB — Bonifico n.1101252230290313.exe Italian banking lure, remcosrat false-positive co-label.
99dc1ea2... 3.89 MB — zira-miszsn.exe OpenCTI co-labels: dropped-by-acrstealer, zigclipper.

Build Stack

  • Compiler / Runtime: Custom Moonshine.Core framework atop .NET Native AOT (PublishAot=true), RID win-x64.
  • Linker: MSVC 14.50 (Visual Studio 2022 v143).
  • Runtime artefacts: System.Private.CoreLib, System.Private.Reflection.Execution, System.Private.TypeLoader, Internal.Runtime.TypeLoader, Moonshine.Core.
  • CLR metadata: Absent — COM_DESCRIPTOR virtual address is 0x0.
  • PE sections: Standard .text, .rdata, .data, .pdata, .rsrc, .reloc plus a custom .gfx encrypted payload section.

Deploy / TTPs

  • Anti-analysis: Native AOT defeats dnSpy/ILSpy/de4dot; no IL to disassemble. Custom runtime (Moonshine.Core) adds a second layer of opacity. ^[raw/analyses/02da37c3.../report.md]
  • Payload staging: Encrypted blob stored in a custom .gfx PE section (entropy ~8.0, 280 KB–11 MB depending on variant); decrypted at runtime by the AOT bootstrap stub. ^[raw/analyses/02da37c3.../report.md]
  • Network: Via natively compiled System.Net.Http — no Winsock imports in IAT. System.Net.SocketsHttpHandler.Http3Support string confirms HTTP/3-capable client. ^[raw/analyses/02da37c3.../report.md]
  • Process manipulation: Imports CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext, OpenProcessToken, AdjustTokenPrivileges — consistent with process injection or hollowing. ^[raw/analyses/02da37c3.../report.md]
  • Masquerade: Version-info fields populated with plausible software company names ("Aether Dynamics Corp.", "Aether Sync Agent"). ^[raw/analyses/02da37c3.../report.md]
  • Social engineering: Purchase-order (PO-YYYYMMDD.exe) and Italian banking (Bonifico n.XXXXXX.docx.exe) filename lures. ^[raw/analyses/02da37c3.../report.md]

Capabilities

  • dotnet-native-aot-compilation-evasion
  • custom-dotnet-runtime-moonshine-core
  • gfx-section-encrypted-payload
  • runtime-http-client-no-iat
  • version-info-masquerade
  • self-contained-runtime-no-clr
  • process-injection-thread-manipulation
  • token-privilege-escalation
  • social-engineering-purchase-order-lure
  • social-engineering-banking-lure

Related Pages