Costura.Fody IL Merging for .NET Malware
Technique: embed all .NET dependencies as compressed resources inside the primary assembly, then load them dynamically at runtime via the Costura.Fody weaver. This collapses a multi-DLL project into a single EXE, hiding dependency boundaries from static analysis and reducing deployable file count.
Detection / Fingerprint
costura.<dllname>.dll.compressedstrings in.rsrcsection ^[sample 667f1f97/strings.txt:4116-4136]ProcessedByFodymarker string in binary ^[sample 667f1f97/strings.txt:7697]- Capa capability:
embed dependencies as resources using Fody/Costura^[sample 667f1f97/capa.txt:178] - Large
.rsrcsection with multipleSystem.Resources.ResourceReaderblobs ^[sample 667f1f97/strings.txt:14-2897]
Implementation Patterns
Malware authors add the Costura.Fody NuGet package to their .NET project. At build time, Fody weaves a module initializer that decompresses embedded DLLs from .rsrc (using System.IO.Compression or LZMA) and loads them via Assembly.Load(byte[]). The result is a single-file EXE that appears to have minimal imports but contains a full dependency tree internally.
Reproduce on Your Own VMs
- Create a .NET Framework 4.7.2 C# console app.
Install-Package Costura.Fody- Add a third-party NuGet reference (e.g.,
Newtonsoft.Json). - Build in Release mode.
- Run
strings.exe output.exe | grep costura— you will seecostura.newtonsoft.json.dll.compressed.
Defensive Countermeasures
- Extract embedded DLLs from
.rsrcusingpython-pefileordnSpyresource view - Monitor for single large
.rsrcsections in .NET executables (entropy >7.5) - Flag
ProcessedByFodyorcostura.*.compressedstrings in endpoint telemetry
Pages Where Observed
- ratonrat
667f1f97d015— full-spectrum .NET RAT with 14 embedded Costura DLLs ^[/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html]