Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain
ID: b7a1ac5a-b535-50a1-af87-1719acde8388
STIX ID: report--b7a1ac5a-b535-50a1-af87-1719acde8388
Feed Name: Seqrite Blog
Seqrite Labs documents a GST-themed phishing campaign targeting Indian businesses and taxpayers that delivers Remcos RAT via a multi-stage .NET loader chain. The attack uses convincing government-branded emails with archive attachments, an initial .NET executable that extracts a bitmap-encoded second-stage assembly, XOR/decode routines to reconstruct perfgurd.dll in memory, fileless execution, privilege escalation via cmstp.exe, persistence via AppData copy and a PowerShell autorun, and C2 infrastructure tied to dynamic DNS services; the report provides IOCs, a C2 IP, and MITRE technique mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
