moonshine-aot-loader
Malware family built on a custom .NET Native AOT runtime framework named Moonshine.Core. Distributed under purchase-order and banking-document social-engineering lures. The threat logic lives in a high-entropy .gfx PE section that is decrypted at runtime, leaving the .text section as a minimal AOT bootstrap stub.
Observed Samples
| SHA-256 Prefix | Size | Timestamp | Filename | Notes |
|---|---|---|---|---|
02da37c3... |
1.05 MB | 2026-05-26 | PO-20260527.exe |
Purchase-order lure, .gfx payload, "Aether Sync Agent" masquerade. ^[raw/analyses/02da37c3.../report.md] |
21bf44a6... |
3.89 MB | — | yea8hw1uN1NGD0za.exe |
OpenCTI co-labels: rat, remcos, remcosrat, zigcryptostealer. Likely mislabelled. |
29eb0a9e... |
1.25 MB | — | raw hash filename | OpenCTI labels: exe, malware-bazaar. Minimal metadata. |
35294411... |
1.25 MB | — | qwe-23wq-e.exe |
OpenCTI co-labels: dropped-by-acrstealer, dropped-by-remusstealer, zigclipper. Likely mislabelled. |
433ff5fd... |
11.9 MB | — | file |
OpenCTI co-labels: d52f85, dropped-by-amadey. Large variant, possibly bundled payload. |
52bd61ba... |
1.56 MB | — | Bonifico n.1101252230290346.docx.exe |
Italian banking lure (unicredit, spam-ita). |
7550b526... |
1.56 MB | — | Bonifico n.1101252230290313.exe |
Italian banking lure, remcosrat false-positive co-label. |
99dc1ea2... |
3.89 MB | — | zira-miszsn.exe |
OpenCTI co-labels: dropped-by-acrstealer, zigclipper. |
Build Stack
- Compiler / Runtime: Custom
Moonshine.Coreframework atop .NET Native AOT (PublishAot=true), RIDwin-x64. - Linker: MSVC 14.50 (Visual Studio 2022 v143).
- Runtime artefacts:
System.Private.CoreLib,System.Private.Reflection.Execution,System.Private.TypeLoader,Internal.Runtime.TypeLoader,Moonshine.Core. - CLR metadata: Absent —
COM_DESCRIPTORvirtual address is 0x0. - PE sections: Standard
.text,.rdata,.data,.pdata,.rsrc,.relocplus a custom.gfxencrypted payload section.
Deploy / TTPs
- Anti-analysis: Native AOT defeats dnSpy/ILSpy/de4dot; no IL to disassemble. Custom runtime (
Moonshine.Core) adds a second layer of opacity. ^[raw/analyses/02da37c3.../report.md] - Payload staging: Encrypted blob stored in a custom
.gfxPE section (entropy ~8.0, 280 KB–11 MB depending on variant); decrypted at runtime by the AOT bootstrap stub. ^[raw/analyses/02da37c3.../report.md] - Network: Via natively compiled
System.Net.Http— no Winsock imports in IAT.System.Net.SocketsHttpHandler.Http3Supportstring confirms HTTP/3-capable client. ^[raw/analyses/02da37c3.../report.md] - Process manipulation: Imports
CreateThread,SuspendThread,ResumeThread,GetThreadContext,SetThreadContext,OpenProcessToken,AdjustTokenPrivileges— consistent with process injection or hollowing. ^[raw/analyses/02da37c3.../report.md] - Masquerade: Version-info fields populated with plausible software company names ("Aether Dynamics Corp.", "Aether Sync Agent"). ^[raw/analyses/02da37c3.../report.md]
- Social engineering: Purchase-order (
PO-YYYYMMDD.exe) and Italian banking (Bonifico n.XXXXXX.docx.exe) filename lures. ^[raw/analyses/02da37c3.../report.md]
Capabilities
dotnet-native-aot-compilation-evasioncustom-dotnet-runtime-moonshine-coregfx-section-encrypted-payloadruntime-http-client-no-iatversion-info-masqueradeself-contained-runtime-no-clrprocess-injection-thread-manipulationtoken-privilege-escalationsocial-engineering-purchase-order-luresocial-engineering-banking-lure
Related Pages
- dotnet-native-aot-rat-compilation — technique deep-dive on Native AOT as anti-analysis
- version-info-masquerade — version-info fabrication pattern
- social-engineering-purchase-order-masquerade — purchase-order lure pattern
- unclassified-dotnet-native-aot-loader — umbrella entity for generic Native AOT samples