logo

Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries

ID: 95c4815f-f715-5d5a-b05f-d93e831e6288

STIX ID: report--95c4815f-f715-5d5a-b05f-d93e831e6288

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

This report details a stealthy Remcos RAT campaign that begins with a phishing email and ZIP attachment containing heavily obfuscated JavaScript which downloads an obfuscated PowerShell loader; the loader reconstructs and decrypts a .NET assembly loaded into memory and injects a PE into aspnet_compiler.exe, enabling C2 communication to 192.3.27.141:8087 and creation of C:\ProgramData\remcos\logs.dat to capture keystrokes and other data. Recommended detections include monitoring PowerShell Base64/obfuscated executions, suspicious outbound connections from system utilities, and blocking known URLs, hashes, and C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.