Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host
ID: ef776cb8-2824-5ea8-ade4-f3e8f4125e7d
STIX ID: report--ef776cb8-2824-5ea8-ade4-f3e8f4125e7d
Feed Name: cybersecurityNews.com
Threat Score
Security researchers uncovered SHADOW#REACTOR, a sophisticated multi-stage Windows malware campaign that uses obfuscated VBS and PowerShell to download base64-encoded payload fragments stored as plain text, validate and reconstruct them into .NET assemblies in memory, and ultimately deploy the Remcos RAT; the pipeline emphasizes evasion through text-only staging, reflective loading, and living-off-the-land techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
