typetechniquecreated2026-08-08updated2026-08-08dotnetobfuscationcompilerexecutable-resource

Costura.Fody IL Merging for .NET Malware

Technique: embed all .NET dependencies as compressed resources inside the primary assembly, then load them dynamically at runtime via the Costura.Fody weaver. This collapses a multi-DLL project into a single EXE, hiding dependency boundaries from static analysis and reducing deployable file count.

Detection / Fingerprint

  • costura.<dllname>.dll.compressed strings in .rsrc section ^[sample 667f1f97/strings.txt:4116-4136]
  • ProcessedByFody marker string in binary ^[sample 667f1f97/strings.txt:7697]
  • Capa capability: embed dependencies as resources using Fody/Costura ^[sample 667f1f97/capa.txt:178]
  • Large .rsrc section with multiple System.Resources.ResourceReader blobs ^[sample 667f1f97/strings.txt:14-2897]

Implementation Patterns

Malware authors add the Costura.Fody NuGet package to their .NET project. At build time, Fody weaves a module initializer that decompresses embedded DLLs from .rsrc (using System.IO.Compression or LZMA) and loads them via Assembly.Load(byte[]). The result is a single-file EXE that appears to have minimal imports but contains a full dependency tree internally.

Reproduce on Your Own VMs

  1. Create a .NET Framework 4.7.2 C# console app.
  2. Install-Package Costura.Fody
  3. Add a third-party NuGet reference (e.g., Newtonsoft.Json).
  4. Build in Release mode.
  5. Run strings.exe output.exe | grep costura — you will see costura.newtonsoft.json.dll.compressed.

Defensive Countermeasures

  • Extract embedded DLLs from .rsrc using python-pefile or dnSpy resource view
  • Monitor for single large .rsrc sections in .NET executables (entropy >7.5)
  • Flag ProcessedByFody or costura.*.compressed strings in endpoint telemetry

Pages Where Observed

  • ratonrat 667f1f97d015 — full-spectrum .NET RAT with 14 embedded Costura DLLs ^[/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html]