logo

Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads

ID: dae1801c-6f0d-5b0d-bf75-79250efc192f

STIX ID: report--dae1801c-6f0d-5b0d-bf75-79250efc192f

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

LevelBlue SpiderLabs observed a sophisticated, reusable multi-vector malware campaign that begins with obfuscated VBS launchers dropping a Base64 PowerShell loader which fetches PNG-embedded payloads from open directories on news4me.xyz; the embedded assembly (PhantomVAI) loads in memory and deploys Remcos RAT and a UAC-bypass DLL, enabling stealthy remote access and privilege escalation. The report identifies attacker infrastructure, examples of IOCs and infection chains, and recommends blocking execution from user-writable folders, enforcing constrained PowerShell, and network-level filtering to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.