"AfterMidnight" lets operators to dynamically load and execute malware payloads on a target device. The primary controller disguises for a self-persisting Windows Assistance DLL and gives safe execution of "Gremlins" by way of a HTTPS dependent Listening Submit (LP) procedure identified as "Octopus"