216.73.216.6

Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse

· Published 18/04/2026 13:40 · Modified 20/04/2026 10:51

Export JSON

Essential information

Published
18/04/2026 13:40
Modified
20/04/2026 10:51
Tags
2026-04-18 appdomainmanager hijacking cloudfront domain fronting financial sector jit trampolining middle east targeting reflective loading sandbox evasion syscall usage
Related entities
4 observables, 19 techniques (mitre), 2 others

Description

A highly sophisticated multi-stage post-exploitation framework targeting organizations in the Middle East and EMEA financial sectors exploits legitimate digitally signed Intel utilities through .NET AppDomainManager mechanism abuse. The attack leverages trusted binary proxy execution, bypassing EDR and antivirus solutions through JIT-based memory execution and using computational delays and cryptographic key derivation loops. Initial access occurs via spear-phishing with Arabic-language decoys impersonating Saudi government documents. Once executed, the framework establishes command-and-control communication through Amazon CloudFront CDN domain fronting, employing reflective DLL loading, direct , and anti-forensic memory cleanup techniques. The modular plugin-based architecture demonstrates capabilities consistent with advanced persistent threat actors, featuring sophisticated evasion mechanisms including PEB-based API resolution, custom PE export walking, and heap-walking cont...

External references