Reverse Engineering RexCry | Unpacking a .NET Loader That Drops StormKitty Infostealer

Reverse Engineering RexCry | Unpacking a .NET Loader That Drops StormKitty Infostealer

Source: YouTube · Malware Research Diary · published Jul 28, 2026 · 33:11

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

This video analyzes "Rex Cry," a .NET-based dropper for the Storm Kitty infostealer, demonstrating how to reverse-engineer its AES decryption logic to extract the embedded payload and configuration.

Key Takeaways:
• Rex Cry is a .NET executable with a 44/70 VirusTotal detection rate, functioning as a dropper for the Storm Kitty infostealer 0:26.
• The dropper embeds the payload at the end of its file; static analysis reveals it uses base64 encoding and a specific magic string to locate the binary data 2:15.
• The presenter uses dnSpy and Python to reverse-engineer the AES decryption, identifying the hardcoded password "1234" used to derive the encryption key 13:50.
• Once decrypted, the Storm Kitty payload reveals capabilities including clipboard manipulation (clipper), keylogging, and webcam activation 17:42.
• The malware targets cryptocurrency wallets by replacing copied Bitcoin addresses with attacker-controlled addresses, with evidence of funds being transferred to external wallets 25:20.
• Unique features include targeting pornographic websites to capture screenshots for potential blackmail or future ransom 29:12.

Rex Cry acts as a straightforward vector for deploying Storm Kitty, relying on predictable encryption keys that simplify analysis while enabling extensive data theft.

Sources:

  • 0:26 Introduction of Rex Cry malware and VirusTotal stats
  • 2:15 Static analysis of the embedded payload structure
  • 13:50 Reverse-engineering the AES decryption key derivation
  • [17:42](

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. Um, welcome back. Um, today um, we're going to analyzing uh, malware um, that is uh, named let me see. The file name is Rex Cry. Um, that we is uploaded to VirusTotal this morning. Um, the detection for it is pretty high, 44 out of 70. Um, and it's a .NET executable. So, .NET um, obfuscated um, cryptor. So, yeah. This might be something interesting. Um, I don't think I've seen this before. Um, let me see. So, the file dropping variety service host run DLL. Um, drop the file. Parent is going to be file.exe. Let's not see what this is. Let's come back. So, let's take a look at the community. It's four just uh, signatures. Okay. Um, Yeah. So, um, checking on the IP address, Telegram, Storm Kitty. So, it might be a Storm Kitty dropper. Um, they also connecting to Pastebin. Beli…