Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse
Essential information
- Published
- 18/04/2026 13:40
- Modified
- 20/04/2026 10:51
- Tags
- 2026-04-18 appdomainmanager hijacking cloudfront domain fronting financial sector jit trampolining middle east targeting reflective loading sandbox evasion syscall usage
- Related entities
- 4 observables, 19 techniques (mitre), 2 others
Description
A highly sophisticated multi-stage post-exploitation framework targeting organizations in the Middle East and EMEA financial sectors exploits legitimate digitally signed Intel utilities through .NET AppDomainManager mechanism abuse. The attack leverages trusted binary proxy execution, bypassing EDR and antivirus solutions through JIT-based memory execution and sandbox evasion using computational delays and cryptographic key derivation loops. Initial access occurs via spear-phishing with Arabic-language decoys impersonating Saudi government documents. Once executed, the framework establishes command-and-control communication through Amazon CloudFront CDN domain fronting, employing reflective DLL loading, direct syscall usage, and anti-forensic memory cleanup techniques. The modular plugin-based architecture demonstrates capabilities consistent with advanced persistent threat actors, featuring sophisticated evasion mechanisms including PEB-based API resolution, custom PE export walking, and heap-walking cont...