Ticket Discounts for Cyber Events

GET ALERTS!

Silent Compromise: Mapping the CrySome RAT

Solution Category Security Analytics
Type Webinar
Organization LevelBlue
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Technical walkthrough of a real-world CrySome RAT infection, from initial phishing lure to persistent remote access.
  • Covers multi-stage infection chains, privilege escalation, defense evasion and credential harvesting techniques.
  • Provides Indicators of Compromise (IOCs) for defenders to detect and disrupt similar intrusions.
  • Demonstrates MDR SOC team triage and containment procedures used during the incident.
  • Designed for security analysts, incident responders and SOC teams at mid to large enterprises.

About the Event

Silent Compromise: Mapping the CrySome RAT is a 45-minute virtual webinar hosted by LevelBlue. The session is led by Sean Shirley, Cyber Threat Intelligence Analyst at LevelBlue, who deconstructs a documented cyberattack involving the CrySome Remote Access Trojan. The webinar follows the complete infection chain of a real incident, examining how attackers gained initial access, escalated privileges, evaded defenses and established persistent command-and-control (C2) access.

CrySome RAT Infection Chain Analysis

The session begins with the initial compromise vector: a phishing email disguised as a freight document. From there, the analysis traces the multi-stage infection process, showing how the modular CrySome RAT deploys its capabilities. The malware enables persistent remote access and credential harvesting, allowing attackers to maintain C2 communication with compromised systems. The webinar examines how the campaign leverages publicly available tools, making it representative of techniques defenders are likely to encounter.

Incident Response and Containment

Beyond malware analysis, the webinar covers how LevelBlue’s Managed Detection and Response (MDR) SOC team identified, triaged and contained the incident. This portion offers practical insight into detection workflows and containment strategies that security teams can apply when responding to similar threats. Attendees will receive IOCs associated with the CrySome RAT campaign to support their own detection efforts.

Who Should Attend

This webinar is intended for cybersecurity professionals responsible for threat detection, malware analysis and incident response. Relevant roles include security analysts, threat intelligence analysts, incident responders, SOC team members and IT security managers. The technical content is suited to practitioners at mid to large enterprises, managed security service providers (MSSPs) and organizations with dedicated security operations functions. Teams seeking to improve their ability to recognize phishing campaigns, trace multi-stage infections and strengthen containment procedures will find the session applicable to their work.