Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

28 Minute Watch Sean Shirley |
Cyber Threat Intelligence Analyst
Karl Sigler |
Senior Research Manager

A phishing email disguised as a routine freight document was all it took. In this session, LevelBlue's Sean Shirley walks through the full CrySome RAT infection chain, from initial execution through privilege escalation and defense evasion, to inside the payload itself. Then he breaks down how the modular CrySome RAT provides the attacker with persistent remote access, facilitates post-exploitation activities, harvests user credentials, and enables continued C2 access over the compromised system.  

This is a hands-on technical session deconstructing how the LevelBlue MDR SOC team triaged and contained a structured infection chain.

You'll learn:

  • The mechanics of a modern malware campaign using publicly available tooling

  • How a phishing lure disguised as a routine freight document led to a multi-stage infection

  • IOCs defenders can watch for to disrupt an intrusion

Watch the Webinar

Related Resources

Current: resourceswebinarssilent-compromise-mapping-the-crysome-rat-infection-chain
Resource: resourceswebinars9000-irs-later-the-11-essential-cybersecurity-controls
Webinar

9,000+ IRs Later: The 11 Essential Cybersecurity Controls

Current: resourceswebinarssilent-compromise-mapping-the-crysome-rat-infection-chain
Resource: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Webinar

US Water Utility Cyberattacks:​ What the Exposure Data Reveals

Current: resourceswebinarssilent-compromise-mapping-the-crysome-rat-infection-chain
Resource: resourceswebinarscommunicating-ai-enabled-enterprise-risk-to-business-leaders
Webinar

Communicating AI-Enabled Enterprise Risk to Business Leaders