Security researchers at Point Wild have uncovered a new Windows RAT campaign that uses a multi-layered infection chain to establish persistent, in-memory access to compromised systems and steal sensitive data. The analysis revealed that the malware relies on standard Windows components for execution and persistence, limiting the number of objects written to disk.
See also: PyPI: Fake Python spellchecker packages delivered RAT malware

The activity, analyzed by the Lat61 , involves a .NET-based, modular remote access Trojan (Pulsar RAT) that supports live, interactive control by operators. The malware's reliance on in-memory execution and living-off-the-land techniques limits the effectiveness of file-based detection tools, the researchers noted in a blog post.
“The malware exhibits advanced anti-analysis techniques, including anti-VM, anti-debugging, and process injection detection, along with extensive credential collection, monitoring, and remote system control capabilities,” they said. “The stolen data is exported as ZIP files via Discord webhooks and Telegram bots.”
The infection chain begins with a small batch script that establishes persistence via a per-user Run Registry key. Rather than deploying a full executable, the script launches a PowerShell-based loader, reducing the likelihood of direct detection by traditional endpoint security tools. This PowerShell loader decodes and executes shellcode created using Donut, an open-source framework commonly used to convert .NET assemblies into location-independent shellcode.
The shellcode injects the payload directly into memory, avoiding the need to write a portable executable to disk.
See also: Multi-stage Phishing Campaign Targets Russia with Amnesia RAT

By operating entirely in memory after initial execution, the malware limits the effectiveness of file-based scanning and static analysis. Point Wild researchers noted that the attack, which blends in with normal Windows activity, requires behavioral or memory-focused telemetry. Once loaded, the malware deploys a heavily obfuscated .NET component that serves as the underlying execution framework for the operation.
The .NET payload implements a remote access Trojan that allows operators to directly interact with compromised systems. Unlike many commercial RATs that rely on periodic checks, this malware supports live command handling, allowing attackers to issue instructions and receive responses in near real-time.
This interactive design allows operators to perform reconnaissance, manipulate files, execute commands, and manage persistence dynamically based on what they observe on the infected computer. Alongside the RAT functionality, the malware includes an information-stealing component that collects sensitive system data. While the disclosure did not attribute the stealer to a specific malware family, researchers noted that it operates in parallel with the RAT, allowing data collection to continue while operators actively interact with the system.
Persistence is maintained through Registry-based autorun entries and is enhanced by the malware’s ability to re-establish execution if interrupted. The use of obfuscation throughout the .NET payload further complicates reverse engineering and slows down analysis. Point Wild emphasized that the campaign’s effectiveness is due to the disciplined execution of living-off-the-land binaries, memory payloads, and obfuscated managed code. Together, they make detection difficult.
See also: Hackers use LinkedIn messages to spread RAT malware

The researchers noted that detecting activity requires monitoring process and memory behavior rather than relying on file-based indicators, which include monitoring suspicious PowerShell execution, shellcode injection into running processes, and suspicious persistence via Registry Run keys. Rapid computer isolation and immediate response were emphasized to limit interactive activity and limit data theft once a breach is suspected.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
