VYPR
researchPublished Sep 29, 2026· 1 source

BotHelper RAT Employs Encryption and Live Screen Surveillance for Stealthy Espionage

A new remote access trojan, BotHelper RAT, utilizes encrypted payloads and live screen surveillance to spy on Windows users, bypassing security measures through in-memory decryption and AMSI patching.

A previously undocumented remote access trojan (RAT) named BotHelper RAT has emerged, offering attackers a stealthy method to monitor and control Windows systems. This malware employs a multi-stage approach, beginning with a small starter program that profiles the infected machine before establishing contact with a remote server. Crucially, BotHelper RAT bypasses certificate checks during this communication, enabling it to download and decrypt its main payload directly in memory, making it significantly harder for traditional security tools to detect.

The initial infection vector for BotHelper RAT remains unclear, but the starter program is designed to be inconspicuous. Once executed, it gathers system information such as the computer name, user, processor, and memory details. This information is then sent over HTTPS to a command-and-control (C2) server. The server responds by sending an encrypted file, which the starter program decrypts and executes in memory. This technique of in-memory decryption is a common evasion tactic used by modern malware to avoid leaving traces on disk.

Researchers from Point Wild identified BotHelper RAT after tracing the infection chain from the initial program to its sophisticated surveillance capabilities. The decrypted payload is written to the temporary folder, often disguised as a legitimate Microsoft Edge component, to further blend in. To ensure persistence, the RAT creates a hidden copy of itself and establishes a scheduled task that relaunches the malware every 30 minutes, a common tactic seen in other Windows RAT operations.

BotHelper RAT's core functionality includes extensive live screen surveillance. It can capture the entire visible desktop, compress frames into JPEGs, and stream them to the C2 server at a rate of up to three frames per second with a JPEG quality of 40. This real-time viewing capability allows attackers to observe user activity, potentially exposing sensitive information like emails, internal applications, credentials, and security prompts without directly exfiltrating files.

Beyond screen capture, BotHelper RAT boasts a comprehensive set of remote control features. It can execute arbitrary commands via Command Prompt or PowerShell, download and run additional files, monitor the clipboard for sensitive data (potentially for cryptocurrency address substitution), display messages to the user, and even restart or shut down the system. The malware also supports loading additional DLL plugins at runtime, indicating a modular design that can be expanded with new functionalities.

A significant evasion technique employed by BotHelper RAT is its patching of the Windows Antimalware Scan Interface (AMSI) before initiating its client functions. This action disables a key security feature that allows security products to inspect scripts and code before execution, further hindering detection efforts. This behavior is consistent with advanced loader evasion methods designed to conceal final payloads until runtime.

Defenders investigating potential BotHelper RAT infections should focus on isolating the affected host, inspecting scheduled tasks, and searching for hidden files. Indicators of compromise include suspicious outbound HTTPS connections, executables in the temporary folder masquerading as browser components, and unusual screen-capture or image-upload activity. Simply removing the visible executable may not be sufficient due to the persistence mechanisms in place.

Organizations are advised to implement endpoint security solutions capable of detecting behavioral anomalies across the entire attack chain, including certificate validation bypasses, in-memory payload decryption, AMSI tampering, and the creation of new scheduled tasks. Resetting potentially exposed credentials and examining active sessions are also critical steps, as live screen views can reveal information that traditional file-based alerts might miss. BotHelper RAT represents a potent combination of stealth, persistence, and intrusive surveillance, posing a significant threat for espionage and potential financial theft.

Synthesized by Vypr AI