logo

Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi-Stage Loader

ID: 3cb8d858-73d2-58b3-959e-efb0b607993c

STIX ID: report--3cb8d858-73d2-58b3-959e-efb0b607993c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

Author: Tushar Subhra Dutta

...
...

A phishing campaign targeting users in India delivers a multi-stage, in-memory loader hidden in a deceptive "GST Debit Note" .NET executable that ultimately deploys Remcos RAT (and other commodity stealers) using steganographic resource embedding and process hollowing; the malware achieves persistence, credential/cookie theft, audio/webcam capture, and exfiltration to identified C2 IPs, and the report includes multiple MD5 hashes and IP indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.