Based on technical sandbox analysis and threat intelligence, is identified as a malicious executable often associated with information stealers or remote access trojans (RATs) . It typically employs social engineering to trick users into execution. Technical Summary File Type: PE32+ executable (Windows 64-bit).
Persistent malware that installs itself into the system's startup routine to ensure it runs every time the computer boots. NightFarm.exe
The process opens and modifies files within the user's AppData directory, which is a common tactic for harvesting browser credentials, session cookies, or cryptocurrency wallet data. Based on technical sandbox analysis and threat intelligence,
According to behavioral reports from Triage , the file performs the following actions upon execution: NightFarm.exe