ConfuserEx is an open-source protector and obfuscator for .NET assemblies. It is used to hinder static analysis and reverse engineering through control-flow obfuscation, symbol renaming, anti-tamper protections, proxy-call indirection, and constant encoding. Threat actors commonly apply ConfuserEx to Windows .NET loaders, remote-access trojans, stealers, ransomware, and first-stage implants to impede decompilation and conceal payload-loading logic. It has been observed in malware operations involving PureCrypter and PureLogs, DarkCloud Stealer, SectopRAT, Hidden Tear-derived ransomware, and activity associated with UAC-0057/UNC1151. ConfuserEx is a defensive-evasion utility rather than a malware family or a payload itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The dropped DLL, which we will later refer to as the first stage implant, is written in C# and obfuscated using ConfuserEx.
The dropped DLL, which we will later refer to as the first stage implant, is written in C# and obfuscated using ConfuserEx.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The operators are using open-source .NET obfuscators such as Obfuscar, NETShield and ConfuserEx to increase the evasiveness of their crypter stub.
To be fully undetectable, the Ranion team has consistently relied on the ConfuserEx project... It is a free and open-source obfuscator that makes malware harder to analyze by “protecting” .NET applications through symbol renaming, anti-debugging, encryption, compression, and other functions. ... MITRE ATT&CK information Defense Evasion - T1027.002: Software Packing
String Protection : C2 host, port, mutex, installation path, and other configuration strings are encrypted ... The C2 host/port cannot be extracted statically
It is further obfuscated using ConfuserEx, disguised as a Python installer
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET obfuscation/protection tool used to protect the intermediate loaders that decrypt and launch PureLog Stealer in memory.
A .NET obfuscator/protector used to hinder analysis of the PureLogs .NET component.
.NET obfuscator used to protect the loader executables (e.g., control-flow flattening, opaque predicates, dead-code injection) to hinder static analysis and reverse engineering.
A publicly available .NET obfuscator used here to protect/obfuscate first-stage C# downloader/implant DLLs from analysis and signature-based detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.