Ticket Discounts for Cyber Events

GET ALERTS!

Silent Compromise: Mapping the CrySome RAT

Solution Category Security Analytics
Type Webinar
Organization LevelBlue
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Technical walkthrough of a real-world CrySome RAT infection chain, from initial phishing email to command-and-control access
  • Covers privilege escalation, defense evasion, credential harvesting and payload analysis techniques
  • Demonstrates how an MDR SOC team triaged and contained the attack
  • Provides indicators of compromise (IOCs) for defenders to identify similar intrusions
  • Designed for SOC analysts, threat intelligence professionals and incident responders

About the Webinar

Silent Compromise: Mapping the CrySome RAT is a 45-minute technical webinar hosted by LevelBlue. The session deconstructs a real-world cyberattack involving the CrySome Remote Access Trojan, examining each stage of the infection chain in detail. Sean Shirley, Cyber Threat Intelligence Analyst at LevelBlue, leads the walkthrough.

The attack began with a phishing email disguised as a routine freight document. The webinar traces the progression from this initial compromise through privilege escalation, defense evasion techniques and eventual payload deployment. Attendees will see how the modular CrySome RAT establishes persistent remote access and enables post-exploitation activities including credential harvesting and continued command-and-control communication.

Technical Focus Areas

The session examines the mechanics of a modern malware campaign that leverages publicly available tooling. Key technical areas include:

  • Phishing attack vectors and social engineering tactics
  • RAT architecture and modular capabilities
  • Privilege escalation methods
  • Defense evasion techniques employed by the malware
  • Command-and-control infrastructure analysis

Incident Response and Containment

Beyond malware analysis, the webinar covers how LevelBlue’s MDR SOC team identified, triaged and contained the threat. This practical component offers defenders insight into structured incident response workflows when facing sophisticated RAT infections. The session includes specific IOCs that security teams can use to detect and disrupt similar intrusions in their environments.

Who Should Attend

This webinar is designed for cybersecurity professionals working in security operations, threat intelligence and incident response. Relevant roles include SOC analysts, threat hunters, incident response leads, SOC managers and security team leaders. Organizations seeking to improve their detection and response capabilities against advanced persistent threats will find the technical detail and practical IOCs particularly valuable.