SillyGoXLR Beyond the First Look — UAC Bypass, Persistence, Discord C2, and RAT Capabilities
Summary SillyGoXLR is a fake GoXLR installer that delivers an obfuscated Java stealer and remote-access trojan. During an isolated execution, the sample copied its payload into a Windows-looking location, bypassed UAC, established logon persistence, retrieved remote configuration from GitHub, authenticated a Discord bot, collected browser and host data, captured the desktop, and successfully exfiltrated an archive. The same payload registered commands for shell execution, process and service control, hidden VNC, SOCKS5 proxying, port forwarding, network scanning, keylogging, microphone capture, input blocking, file operations, self-update, and self-destruction. ...