The malware utilizes a "builder" tool that allows attackers to customize and obfuscate the malicious package before deployment. EVLF DEV-The Creator of CypherRAT and CraxsRAT - cyfirma
cypher rat evlf -f suspicious.exe --extract --verify --link --fingerprint Cypher Rat Evlf