logo

Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host

ID: ef776cb8-2824-5ea8-ade4-f3e8f4125e7d

STIX ID: report--ef776cb8-2824-5ea8-ade4-f3e8f4125e7d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Security researchers uncovered SHADOW#REACTOR, a sophisticated multi-stage Windows malware campaign that uses obfuscated VBS and PowerShell to download base64-encoded payload fragments stored as plain text, validate and reconstruct them into .NET assemblies in memory, and ultimately deploy the Remcos RAT; the pipeline emphasizes evasion through text-only staging, reflective loading, and living-off-the-land techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.