A newly discovered remote access trojan (RAT) called BotHelper is able to silently spy on Windows users by capturing live screen activity and giving attackers remote control of the system. This threat combines encrypted payloads, disguised file names, and automated persistence to evade detection. The result is a malware that quietly infiltrates devices and opens a view into everything the user does.
How BotHelper RAT Operates
The attack begins innocuously: a small starter program is delivered to the target, though it is not yet known how it reaches systems. This starter immediately profiles the machine—gathering information such as device name, user account, CPU, and memory—and then connects to a remote server over HTTPS. Crucially, the connection bypasses certificate validation, letting it avoid one common security barrier. What comes back is an encrypted data payload without a proper Windows executable header or readable strings, hidden from antivirus tools. At runtime, the file is decrypted in memory using a position-dependent XOR routine, revealing a .NET-based payload.
Once active, BotHelper drops its main executable in the user’s temporary folder under a name mimicking a Microsoft Edge component. It then installs a hidden copy of itself and creates a scheduled task to relaunch every 30 minutes—classic persistence steps that ensure it can return even after partial cleanup.
Capabilities: Surveillance, Control, and Evasion
BotHelper’s core feature is live screen surveillance. Its operators issue commands like Screenshot and ScreenStreamStart. This enables a continuous visual stream at roughly three frames per second, using JPEG compression set to a quality level of 40. Capture resolution observed during monitoring was 1440×810 pixels, with frames streamed every 333 milliseconds. Even if a capture fails, the stream continues. The design also allows delays to lower the rate to 20 fps under some conditions.
Beyond screen monitoring, BotHelper grants remote control via Command Prompt or PowerShell, lets attackers download and run other files, and even load DLL plugins dynamically. It also monitors the clipboard—potentially to substitute cryptocurrency addresses—can display messages, and can reboot or shut down the PC. The RAT disables or patches parts of the Windows Antimalware Scan Interface (AMSI), further limiting tools’ ability to inspect or block its execution.
Persistence, Hidden Indicators, and Detection Challenges
Persistence techniques include creating scheduled tasks that revive the malware every half hour and hiding processes or file copies so they’re not obvious. The encrypted payload ensures that until runtime, security tools won’t catch it through file scanning. File hashes identified include two specific SHA-256 values tied to both the stager and the full RAT executable. Disguised file names like “WindowsUpdate.exe” for the initial stager and “Msedge_proxy.exe” for the RAT are used, stored in the %TEMP% directory under “msedge_proxy.exe.” The malware communicates with a domain called easyllms[.]xyz via endpoints such as ping.php, connect.php, screen_live.php, and others.
Indicators of compromise include unexpected HTTPS outbound traffic, scheduled tasks set to run periodically, files in temporary folders using browser-like names, and activity linked to screen capturing or image uploads. Importantly, merely deleting visible files may not neutralize the threat, since scheduled tasks and hidden instances can rebuild the infection.
To respond after detecting BotHelper, organizations are advised to isolate the compromised host, review scheduled tasks, inspect hidden copies of executables, reset credentials that may have been exposed, and monitor for unusual session activities. Endpoint defenses should also look for patterns like certificate validation bypass, AMSI tampering, in-memory payload decryption, and unrecognized child processes.
What sets BotHelper apart is that it packs a potent mix of live screen surveillance and robust control capabilities into a compact toolkit designed for stealth. The RAT isn’t just about stealing files—it’s about seeing everything, from security prompts to documents, in real time, often undetectable by traditional tools.
The advent of tools like BotHelper underscores how attackers continue to evolve: not simply stealing data after compromise, but watching, manipulating, and altering systems in near real time. What to watch for next is whether BotHelper variants begin incorporating even more evasive measures—such as deeper system hooks or machine learning to bypass anomaly detection—and how defenders will adjust policies and endpoint tools to detect behavioral chains rather than just individual suspicious files.