📅 Thursday, October 8, 2026 | 10am CT/ 10am BST
A phishing email disguised as a routine freight document was all it took. In this session, LevelBlue's Sean Shirley walks through the full CrySome RAT infection chain, from initial execution through privilege escalation and defense evasion, to inside the payload itself. Then he breaks down how the modular CrySome RAT provides the attacker with persistent remote access, facilitates post-exploitation activities, harvests user credentials, and enables continued C2 access over the compromised system.
This is a hands-on technical session deconstructing how the LevelBlue MDR SOC team triaged and contained a structured infection chain.
You’ll learn
-
The mechanics of a modern malware campaign using publicly available tooling
-
How a phishing lure disguised as a routine freight document led to a multi-stage infection
-
IOCs defenders can watch for to disrupt an intrusion