logo

Fileless Execution: PowerShell Based Shellcode Loader Executes Remcos RAT

ID: 8acc1ed9-c2b7-52d6-bd41-fb25860c5b27

STIX ID: report--8acc1ed9-c2b7-52d6-bd41-fb25860c5b27

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2025-05-15

Date Updated: 2026-04-28

Author: Akshay Thorve

...
...

Qualys Threat Research Unit describes a PowerShell-based fileless shellcode loader used to deliver and execute a Remcos RAT variant via weaponized LNK files and mshta.exe; the analysis details deobfuscation, in-memory PE loading, API resolution, persistence (registry run keys, mutex, process hollowing), UAC bypass attempts, C2 communications (domain/IPs, TLS port 2025), extensive espionage capabilities (keylogging, credential theft, screenshots, webcam/microphone capture), MITRE technique mappings, IOCs (hashes, domain, IPs, mutex), and recommended EDR/PowerShell/AMSI defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.