logo

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

ID: b7a1ac5a-b535-50a1-af87-1719acde8388

STIX ID: report--b7a1ac5a-b535-50a1-af87-1719acde8388

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Vaibhav Billade

...
...

Seqrite Labs documents a GST-themed phishing campaign targeting Indian businesses and taxpayers that delivers Remcos RAT via a multi-stage .NET loader chain. The attack uses convincing government-branded emails with archive attachments, an initial .NET executable that extracts a bitmap-encoded second-stage assembly, XOR/decode routines to reconstruct perfgurd.dll in memory, fileless execution, privilege escalation via cmstp.exe, persistence via AppData copy and a PowerShell autorun, and C2 infrastructure tied to dynamic DNS services; the report provides IOCs, a C2 IP, and MITRE technique mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.