typeentityconfidencelowcreated2026-06-19updated2026-08-07loaderdotnetanti-analysisevasionmalware-family

unclassified-dotnet-native-aot-loader

Umbrella label for malware built with .NET Native AOT (PublishAot). The AOT compilation strips all CLR metadata, rendering the binary opaque to conventional .NET analysis tools while inflating file size with inlined BCL runtime. Two observed morphs: (1) encrypted payload embedded as a custom-named PE resource, and (2) export-table semantic-jargon obfuscation masquerading as a legitimate Chromium/Edge ELF DLL with no observable payload resource.

Observed Samples

SHA-256 Prefix Size Timestamp Notes
fbc07658... 10 MB —
ef48ae9e... 5.5 MB 2024-07-29
9a69ad1b... 2.5 MB 2025-10-22

Build Stack

  • Compiler: .NET 8+ SDK with PublishAot=true, RID win-x64.
  • Linker: MSVC 14.38–14.40 (Visual Studio 2022 v143).
  • Runtime artefacts: System.Private.CoreLib, Internal.Runtime.TypeLoader, RhGetGcTotalMemory, CanonType, UniversalCanonType, DotNetRuntimeDebugHeader export.
  • CLR metadata: Absent — COM_DESCRIPTOR virtual address is 0x0.

Deploy / TTPs

  • Anti-analysis: Native AOT defeats dnSpy/ILSpy/de4dot; no IL to disassemble. ^[raw/analyses/ef48ae9e.../report.md]
  • Payload staging: Encrypted blob stored as custom BINARY or RCDATA resource; decrypted at runtime by AOT-compiled stub. ^[raw/analyses/ef48ae9e.../report.md]
  • Network: Via natively compiled System.Net.Http — no Winsock imports in IAT. ^[raw/analyses/ef48ae9e.../report.md]
  • Masquerade: Version-info fields populated with bland or nonsensical strings (e.g., SetVersionHasValue). ^[raw/analyses/ef48ae9e.../report.md]

Capabilities

  • dotnet-native-aot-compilation-evasion
  • custom-resource-encrypted-payload
  • runtime-http-client-no-iat
  • version-info-masquerade
  • self-contained-runtime-no-clr
  • chromium-edge-elf-export-masquerade
  • semantic-jargon-export-obfuscation

Related Pages